Zoom¶à¿îÈí¼þÔ¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-07-17Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-13567£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
ÊÜÓ°ÏìµÄ°æ±¾
MacµÄZoom Client 4.4.53932.0709֮ǰ°æ±¾
Îó²î¸ÅÊö
ZoomÊÇÆóÒµÊÓÆµÍ¨Ñ¶ÁìÓòµÄÏòµ¼Õߣ¬£¬ÊÇÊÓÆµºÍÒôƵ¾Û»á£¬£¬Ì¸ÌìºÍÍøÂç×êÑлá×îÊܽӴýºÍ×î¿É¿¿µÄÔÆÆ½Ì¨Ö®Ò»¡£¡£¡£
ÔÚ7ÔÂ10ÈÕ¹ãÊܽӴýÇÒÆÕ±éʹÓõÄZoomÊÓÆµ¾Û»áÈí¼þÖÐÅû¶Òþ˽Îó²îCVE-2019-13450µÄÔÓÂҺͿֻŻ¹Ã»Óп¢Ê¡£¡£¡£Èí¼þÍâµØ×°ÖõÄwebЧÀÍÆ÷²»µ«ÔÊÐíÈκÎÍøÕ¾·¿ªÄúµÄ×°±¸ÍøÂçÉãÏñÍ·£¬£¬²¢ÇÒ»¹¿ÉÒÔÈúڿÍÔ¶³ÌÍêÈ«¿ØÖÆÄúµÄApple MacÅÌËã»ú¡£¡£¡£
¾Ý±¨µÀ£¬£¬ÓÃÓÚmacOSµÄ»ùÓÚÔÆµÄZoom¾Û»áƽ̨Ҳ±»·¢Ã÷ÈÝÒ×Êܵ½ÁíÒ»¸öÑÏÖØÎó²î£¨CVE-2019-13567£©µÄÓ°Ï죬£¬¸ÃÎó²î¿ÉÄÜÔÊÐíÔ¶³Ì¹¥»÷ÕßÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£
ÕâÁ½¸öÎó²î¶¼Ô´ÓÚÒ»¸öÓÐÕùÒéµÄÍâµØWebЧÀÍÆ÷£¬£¬ÔÚ¶Ë¿Ú19421ÉÏÔËÐУ¬£¬Zoom¿Í»§¶Ë×°ÖÃÔÚÓû§µÄÅÌËã»úÉÏÒÔÌṩµã»÷¼ÓÈ빦Ч¡£¡£¡£Çå¾²Ñо¿Ö°Ô±Ç¿µ÷µÄÖ÷ÒªÊÇÁ½¸öÎÊÌ⣺Ê×ÏÈ£¬£¬ÍâµØÐ§ÀÍÆ÷¡°²»Çå¾²¡±Í¨¹ýHTTPÎüÊÕÏÂÁ£¬ÔÊÐíÈκÎÍøÕ¾ÓëÖ®½»»¥£¬£¬Æä´Î£¬£¬µ±Óû§´ÓÆäϵͳÖÐɾ³ýZoom¿Í»§¶Ëʱ£¬£¬Ëü²»»á±»Ð¶ÔØ£¬£¬ÈÃËûÃÇÓÀԶųÈõ¡£¡£¡£
ÏÂÃæÁгöµÄZoomÈí¼þ¹²ÓÐ10¸ö¸üÃû°æ±¾£¬£¬¿ÉÔÚÊг¡ÉÏÂòµ½¡£¡£¡£ËùÓÐÕâЩÊÓÆµ¾Û»áÈí¼þ¶¼ÔÚÊÂÇ飬£¬²¢°üÀ¨ÏàͬµÄÎó²î£¬£¬Ê¹Óû§Ò²ÃæÁÙÔ¶³ÌºÚ¿Í¹¥»÷µÄΣº¦£º
Zhumu
Telus Meetings
BT Cloud Phone Meetings
Office Suite HD Meeting
AT&T Video Meetings
BizConf
Huihui
UMeeting
Zoom CN
AppleÒÑÍÆËÍÁËËùÓÐmacOSÓû§µÄ¸üУ¬£¬×Ô¶¯É¾³ýZoom WebЧÀÍÆ÷¶øÎÞÐèÈκÎÓû§½»»¥¡£¡£¡£
Îó²îÑéÖ¤
https://twitter.com/karanlyons/status/1150774640899317760¡£¡£¡£
ÐÞ¸´½¨Òé
RingCentralÐÞ²¹ÁËÎó²î£¬£¬Çë¸üÐÂÖÁRingCentral Meetings MacOS app v7.0.151508.0712£ºhttps://support.ringcentral.com/s/article/11201-Meetings-Security-Advisory?language=en_US¡£¡£¡£
½¨ÒéÓû§Í¨¹ýÔËÐÐGitHubÉϵÄÑо¿Ö°Ô±ÌṩµÄÏÂÁîÊÖ¶¯É¾³ýÒþ²ØµÄWebЧÀÍÆ÷£ºhttps://gist.github.com/karanlyons/1fde1c63bd7bb809b04323be3f519f7e¡£¡£¡£
²Î¿¼Á´½Ó
https://thehackernews.com/2019/07/zoom-video-conferencing-hacking.html


¾©¹«Íø°²±¸11010802024551ºÅ