ÊÔÓÃAppÐ¶ÔØºóÖ±½Ó¿Û·Ñ£¬£¬£¬£¬£¬È«Çò½ü6ÒÚAndroidÓû§ÖÐÕУ»£»Î¢ÈíÐû²¼1ÔÂOfficeÇå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´3¸öRCEÎó²î

Ðû²¼Ê±¼ä 2020-01-17


1.ÊÔÓÃAppÐ¶ÔØºóÖ±½Ó¿Û·Ñ£¬£¬£¬£¬£¬È«Çò½ü6ÒÚAndroidÓû§ÖÐÕÐ


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


SophosÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»×éеÄfleeceware APP£¬£¬£¬£¬£¬ÕâЩAPPÒѾ­±»Áè¼Ý6ÒÚAndroidÓû§ÏÂÔØ×°Öᣡ£¡£¡£ ¡£fleecewareÊÇÖ¸¹È¸èPlayÊÐËÁÖб£´æµÄÒ»ÖÖÐÂÐͽðÈÚڲƭÐÐΪ£¬£¬£¬£¬£¬ÕâЩAPPÀÄÓÃAndroidÓ¦ÓõÄÊÔÓÃÆÚ¹¦Ð§ÏòÓû§ÊÕ·Ñ¡£¡£¡£¡£ ¡£Ä¬ÈÏÇéÐÎÏÂAndroidÓû§ÔÚ×¢²áʹÓþßÓÐÊÔÓÃÆÚµÄAPPʱ±ØÐèÊÖ¾Ù´ë·ÏÊÔÓ㬣¬£¬£¬£¬È»¶ø´ó´ó¶¼Óû§Ö»ÊÇÔÚ²»Ï²»¶µÄʱ¼äÐ¶ÔØAPP£¬£¬£¬£¬£¬¾ø´ó´ó¶¼¿ª·¢Õß½«ÕâÖÖÐ¶ÔØÐÐΪÊÓΪ×÷·ÏÊÔÓ㬣¬£¬£¬£¬µ«Ò»Ð©¿ª·¢ÕßÔÚÓû§Ð¶ÔغóûÓÐ×÷·ÏÊÔÓò¢ÇÒ¼ÌÐøÊÕ·Ñ¡£¡£¡£¡£ ¡£Sophos×î³õ·¢Ã÷µÄ24¸öAPP°üÀ¨¶þάÂëɨÃèÆ÷¡¢ÅÌËãÆ÷µÈ£¬£¬£¬£¬£¬ËüÃÇÒÔÕâÖÖ·½·¨ÏòÓû§ÊÕȡÿÄê100ÃÀÔªµ½240ÃÀÔªµÄ¶©ÔÄÓöÈ¡£¡£¡£¡£ ¡£ÔÚ¿ËÈÕÐû²¼µÄÒ»·Ý±¨¸æÖУ¬£¬£¬£¬£¬Sophos·¢Ã÷ÁËÁíÍâ25¸ö´ËÀàAPP£¬£¬£¬£¬£¬Æä×Ü×°ÖÃÁ¿Áè¼Ý6ÒÚ£¬£¬£¬£¬£¬ÍêÕûµÄAPPÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£ ¡£


  Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/more-than-600-million-users-installed-android-fleeceware-apps-from-the-play-store/


2.΢ÈíÐû²¼1ÔÂOfficeÇå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´3¸öRCEÎó²î


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


΢ÈíÔÚ1ÔÂOfficeÇå¾²¸üÐÂÖÐΪ5¸ö²î±ðµÄ²úÆ·Ðû²¼ÁË×ܹ²7¸öÇå¾²¸üкÍ3¸öÀۼƸüУ¬£¬£¬£¬£¬ÆäÖÐ6¸ö¸üÐÂÓëÔ¶³Ì´úÂëÖ´ÐÐÎó²îÓйØ¡£¡£¡£¡£ ¡£ÕâЩRCEÎó²î±»¸ú×ÙΪCVE-2020-0650¡¢CVE-2020-0651ºÍCVE-2020-0652£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄ²úÆ·°üÀ¨Office 2016¡¢Office 2013¡¢Office 2010¡¢Excel 2016¡¢Excel 2013ºÍExcel 2010¡£¡£¡£¡£ ¡£±ðµÄ±»¸ú×ÙΪCVE-2020-0647µÄÁíÒ»¸öÎó²îÊÇÓ°ÏìOffice Online ServerµÄÓÕÆ­Îó²î£¬£¬£¬£¬£¬ËüÊÇÓÉ¿çÓòͨѶÖеÄԭʼÑéÖ¤²»×¼È·ÒýÆðµÄ£¬£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÊÜÓ°ÏìµÄϵͳÉϾÙÐпçÓò¹¥»÷¡£¡£¡£¡£ ¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-office-january-security-updates-fix-code-execution-bugs/


3.VMwareÐû²¼VMware Tools 11£¬£¬£¬£¬£¬ÐÞ¸´10°æ±¾ÖеÄLPEÎó²î


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


VMwareÒÑÐû²¼VMware Tools 11.0.0£¬£¬£¬£¬£¬ÐÞ¸´Á˰汾10.xyÖеÄÍâµØÌáȨÎó²î£¨CVE-2020-3941£©¡£¡£¡£¡£ ¡£¸ÃÎó²î±»¹éÀàΪ¾ºÕùÌõ¼þÎó²î£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜʹÓôËÎó²îÔÚÐéÄâ»úÖÐÌáÉýÌØÈ¨¡£¡£¡£¡£ ¡£¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.8·Ö¡£¡£¡£¡£ ¡£±ðµÄ£¬£¬£¬£¬£¬VMware»¹ÐÞ¸´ÁËWorkspace ONE SDKÖеÄÐÅϢй¶Îó²î£¨CVE-2020-3940£©£¬£¬£¬£¬£¬¸ÃÎó²îÓ°ÏìÁËÏà¹ØµÄiOSºÍAndroid APP£¬£¬£¬£¬£¬°üÀ¨Workspace ONE Boxer¡¢Content¡¢Intelligent Hub¡¢Notebook¡¢People¡¢PIV-D¡¢WebÒÔ¼°ÊÊÓÃÓÚApache CordovaºÍXamarinµÄSDK²å¼þ¡£¡£¡£¡£ ¡£Æ¾Ö¤Ç徲ͨ¸æ£¬£¬£¬£¬£¬ÈôÊÇÆôÓÃÁËSSL Pinning£¬£¬£¬£¬£¬ÔòÔÚÊÜÓ°ÏìµÄÒÆ¶¯APPºÍWorkspace ONE UEM×°±¸Ð§ÀÍÖ®¼äµÄÖÐÐÄÈË£¨MITM£©¹¥»÷Õß¿ÉÄܲ¶»ñ´«ÊäÖеÄÃô¸ÐÊý¾Ý¡£¡£¡£¡£ ¡£


 Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/96446/security/vmware-tools-and-workspace-one-sdk-flaws.html


4.Peekaboo MomentsÒâÍâй¶80ÍòÓû§µÄÓÊÏäÐÅÏ¢


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Çå¾²Ñо¿Ô±Dan Ehrlich·¢Ã÷Peekaboo Moments APPµÄElasticsearchÊý¾Ý¿â̻¶ÁËÊýǧ¸öÓ¤¶ùµÄÕÕÆ¬ºÍÊÓÆµÒÔ¼°ÖÁÉÙ80Íò¸öµç×ÓÓʼþµØµã¡£¡£¡£¡£ ¡£¸ÃÊý¾Ý¿âÊôÓÚPeekaboo MomentsµÄ¿ª·¢ÉÌBithouse£¬£¬£¬£¬£¬Êý¾Ý¿âÖдæÓÐ7000Íò¸öÈÕÖ¾Îļþ¡£¡£¡£¡£ ¡£³ýÁËÓ¤¶ùµÄÊÓÆµºÍÕÕÆ¬Í⣬£¬£¬£¬£¬¸ÃÊý¾Ý¿â»¹°üÀ¨Ó¤¶ùµÄ³öÉúÈÕÆÚ¡¢Éí³¤ºÍÌåÖØÒÔ¼°¾­¶ÈºÍγ¶ÈλÖÃÊý¾Ý¡£¡£¡£¡£ ¡£±ðµÄ£¬£¬£¬£¬£¬Ð¹Â¶µÄÊý¾ÝÒÉΪPeekaboo MomentsµÄFacebook APIÃÜÔ¿£¬£¬£¬£¬£¬âïÊÑ¿ÉʹÓøÃÃÜÔ¿½«ÕÕÆ¬µÈÐû²¼µ½Facebook¡£¡£¡£¡£ ¡£Æ¾Ö¤EhrlichµÄ˵·¨£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜ»áʹÓÃÕâЩÃÜÔ¿À´»á¼ûÓû§FacebookÒ³ÃæÉϵÄÄÚÈÝ¡£¡£¡£¡£ ¡£BithouseÔÚ½Óµ½±¨¸æºóѸËÙ¶ÔЧÀÍÆ÷¾ÙÐÐÁ˱£»£»¤¡£¡£¡£¡£ ¡£


 Ô­ÎÄÁ´½Ó£º

https://hotforsecurity.bitdefender.com/blog/peekaboo-moments-app-left-baby-videos-photos-and-800000-users-email-addresses-exposed-on-the-internet-22067.html


5.¼ÓÄôóÍøÉÏÒ©µêPlanetDrugsDirectй¶²¿·Ö¿Í»§Ö§¸¶ÐÅÏ¢


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


¼ÓÄôóÍøÉÏÒ©µêPlanetDrugsDirectÕýÔÚͨ¹ýµç×ÓÓʼþ֪ͨ¿Í»§ÆäСÎÒ˽¼ÒºÍ²ÆÎñÐÅÏ¢Êܵ½Êý¾Ýй¶ÊÂÎñµÄÓ°Ïì¡£¡£¡£¡£ ¡£PlanetDrugsDirect³Æ×Ô¼ºÎª¿Í»§Ìṩ»ñµÃ´¦·½Ò©ºÍ·Ç´¦·½Ò©µÄʱ»ú£¬£¬£¬£¬£¬Æä¿Í»§ÊýĿԼΪ40Íò¡£¡£¡£¡£ ¡£Æ¾Ö¤¸ÃÒ©µêµÄ֪ͨ£¬£¬£¬£¬£¬¿ÉÄÜй¶µÄÊý¾Ý°üÀ¨¿Í»§µÄÐÕÃû¡¢×¡Ö·¡¢µç×ÓÓʼþµØµã¡¢µç»°ºÅÂëÒÔ¼°´¦·½µÄÒ½ÁÆÐÅÏ¢ºÍ¸¶¿îÐÅÏ¢£¬£¬£¬£¬£¬µ«Ã»ÓÐÖ¤¾ÝÅú×¢Óû§µÄÃÜÂëÊܵ½Ë𺦡£¡£¡£¡£ ¡£PlanetDrugsDirect»¹Ö¸³ö¸ÃÊÂÎñÏÖÔÚÕýÔÚÊÓ²ìÖУ¬£¬£¬£¬£¬½«¾¡¿ìÌṩ¸ü¶àÏêϸÐÅÏ¢¡£¡£¡£¡£ ¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/online-pharmacy-planetdrugsdirect-discloses-security-breach/


6.Êý°Ù¸öҽѧ³ÉÏñϵͳÔÚÍøÉÏ̻¶ÁËÊý°ÙÍò»¼ÕßµÄÊý¾Ý


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


µÂ¹úÇå¾²³§ÉÌGreenbone³ÆÊý°Ù¸ö¿É¹ûÕæ»á¼ûµÄҽѧ³ÉÏñϵͳÔÚ»¥ÁªÍøÉÏ̻¶ÁËÈ«ÇòÊý°ÙÍò»¼ÕßµÄÊý¾Ý¡£¡£¡£¡£ ¡£¸ÃÏîÑо¿ÖصãÆÊÎöÔÚÍøÉÏ̻¶µÄҽѧͼƬ´æµµºÍͨѶϵͳ£¨PACS£©£¬£¬£¬£¬£¬ÔÚËùÓÐÊÜÆÊÎöµÄPACSЧÀÍÆ÷ÖУ¬£¬£¬£¬£¬ÓпìÒª1/4µÄϵͳ½«Êý¾Ý̻¶ÔÚ»¥ÁªÍøÉÏ¡£¡£¡£¡£ ¡£ÏêϸÀ´Ëµ£¬£¬£¬£¬£¬ÔÚ2019Äê7ÔÂÖÁ2019Äê9ÔÂÖ®¼äÆÊÎöµÄ2300¸öϵͳÖУ¬£¬£¬£¬£¬ÓÐ590¸ö¿É´ÓInternet»á¼û²¢ÇÒδÉèÃÜÂ룬£¬£¬£¬£¬¹²ÓÐÁè¼Ý2450ÍòÌõ»¼ÕßÊý¾Ý̻¶£¬£¬£¬£¬£¬ÔÚ11Ô·ݵÄÑо¿ÖУ¬£¬£¬£¬£¬¸Ã¹«Ë¾Í¸Â¶ÓÐ3500ÍòÌõ»¼Õ߼ͼ¿É¹ûÕæ»á¼û¡£¡£¡£¡£ ¡£ÔÚ9ÔÂÖÁ11ÔÂÖ®¼ä£¬£¬£¬£¬£¬°üÀ¨Ò½ÁÆÍ¼ÏñµÄ̻¶»¼Õ߼ͼÊýÄ¿ÒÑ´Ó440ÍòÔöÌíÁËÒ»±¶£¬£¬£¬£¬£¬µÖ´ï900Íò¡£¡£¡£¡£ ¡£


 Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/unprotected-medical-systems-expose-data-millions-patients