ÊÔÓÃAppÐ¶ÔØºóÖ±½Ó¿Û·Ñ£¬È«Çò½ü6ÒÚAndroidÓû§ÖÐÕУ»Î¢Èí°ä²¼1ÔÂOffice°²È«¸üУ¬½¨¸´3¸öRCE·ì϶
°ä²¼¹¦·ò 2020-01-17
1.ÊÔÓÃAppÐ¶ÔØºóÖ±½Ó¿Û·Ñ£¬È«Çò½ü6ÒÚAndroidÓû§ÖÐÕÐ
Sophos°²È«×êÑÐÈËÔ±·¢ÏÖÁËÒ»×éеÄfleeceware APP£¬ÕâЩAPPÒѾ±»³¬¹ý6ÒÚAndroidÓû§ÏÂÔØ×°Öá£fleecewareÊÇÖ¸¹È¸èPlayÉ̵êÖдæÔÚµÄÒ»ÖÖÐÂÐͽðÈÚÚ²ÆÐÐΪ£¬ÕâЩAPPÀÄÓÃAndroidÀûÓõÄÊÔÓÃÆÚÖ°ÄÜÏòÓû§ÊÕ·Ñ¡£Ä¬ÈÏÇé¿öÏÂAndroidÓû§ÔÚ×¢²áʹÆ÷ÓµÓÐÊÔÓÃÆÚµÄAPPʱ±ØÐëÊÖ¶¯È¡µÞÊÔÓã¬È»¶ø´óÎÞÊýÓû§Ö»ÊÇÔÚ²»Ï²»¶µÄʱ³½Ð¶ÔØAPP£¬¾ø´óÎÞÊý¿ª·¢Õß½«ÕâÖÖÐ¶ÔØÐÐΪÊÓΪȡµÞÊÔÓ㬵«Ò»Ð©¿ª·¢ÕßÔÚÓû§Ð¶ÔغóûÓÐÈ¡µÞÊÔÓò¢ÇÒ³ÖÐøÊÕ·Ñ¡£Sophos×î³õ·¢ÏÖµÄ24¸öAPPÔ̺¬¶þάÂëɨÃèÆ÷¡¢ÍÆËãÆ÷µÈ£¬ËüÃÇÒÔÕâÖÖ·½Ê½ÏòÓû§ÊÕȡÿÄê100ÃÀÔªµ½240ÃÀÔªµÄ¶©ÔÄÓöȡ£ÔÚ½üÈÕ°ä²¼µÄÒ»·Ý»ã±¨ÖУ¬Sophos·¢ÏÖÁËÁí±í25¸ö´ËÀàAPP£¬Æä×Ü×°ÖÃÁ¿³¬¹ý6ÒÚ£¬ÆëÈ«µÄAPPÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/more-than-600-million-users-installed-android-fleeceware-apps-from-the-play-store/
2.΢Èí°ä²¼1ÔÂOffice°²È«¸üУ¬½¨¸´3¸öRCE·ì϶
΢ÈíÔÚ1ÔÂOffice°²È«¸üÐÂÖÐΪ5¸ö·ÖÆçµÄ²úÆ·°ä²¼ÁË×ܹ²7¸ö°²È«¸üкÍ3¸öÀۼƸüУ¬ÆäÖÐ6¸ö¸üÐÂÓëÔ¶³Ì´úÂëÖ´Ðзì϶Óйء£ÕâЩRCE·ì϶±»¸ú×ÙΪCVE-2020-0650¡¢CVE-2020-0651ºÍCVE-2020-0652£¬ÊÜÓ°ÏìµÄ²úÆ·Ô̺¬Office 2016¡¢Office 2013¡¢Office 2010¡¢Excel 2016¡¢Excel 2013ºÍExcel 2010¡£´Ë±í±»¸ú×ÙΪCVE-2020-0647µÄÁíÒ»¸ö·ì϶ÊÇÓ°ÏìOffice Online ServerµÄºýŪ·ì϶£¬ËüÊÇÓÉ¿çÓòͨѶÖеÄÔʼÑéÖ¤²»ÕýÈ·ÒýÆðµÄ£¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚÊÜÓ°ÏìµÄϵͳÉϽøÐпçÓò¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-office-january-security-updates-fix-code-execution-bugs/
3.VMware°ä²¼VMware Tools 11£¬½¨¸´10°æ±¾ÖеÄLPE·ì϶
VMwareÒѰ䲼VMware Tools 11.0.0£¬½¨¸´Á˰汾10.xyÖеı¾µØÌáȨ·ì϶£¨CVE-2020-3941£©¡£¸Ã·ì϶±»¹éÀàΪ¾ºÕùǰÌá·ì϶£¬¹¥»÷Õß¿ÉÄÜÀûÓô˷ì϶ÔÚÐé¹¹»úÖÐÌáÉýÌØÈ¨¡£¸Ã·ì϶µÄCVSSÆÀ·ÖΪ7.8·Ö¡£´Ë±í£¬VMware»¹½¨¸´ÁËWorkspace ONE SDKÖеÄÐÅϢй¶·ì϶£¨CVE-2020-3940£©£¬¸Ã·ì϶ӰÏìÁËÓйصÄiOSºÍAndroid APP£¬Ô̺¬Workspace ONE Boxer¡¢Content¡¢Intelligent Hub¡¢Notebook¡¢People¡¢PIV-D¡¢WebÒÔ¼°ºÏÓÃÓÚApache CordovaºÍXamarinµÄSDK²å¼þ¡£Æ¾¾Ý°²È«²¼¸æ£¬ÈôÊÇÆôÓÃÁËSSL Pinning£¬ÔòÔÚÊÜÓ°ÏìµÄÒÆ¶¯APPºÍWorkspace ONE UEMÉ豸·þÎñÖ®¼äµÄÖÐÑëÈË£¨MITM£©¹¥»÷Õß¿ÉÄܲ¶»ñ´«ÊäÖеÄÃô¸ÐÊý¾Ý¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/96446/security/vmware-tools-and-workspace-one-sdk-flaws.html
4.Peekaboo MomentsÒâ±íй¶80ÍòÓû§µÄÓÊÏäÐÅÏ¢
°²È«×êÑÐÔ±Dan Ehrlich·¢ÏÖPeekaboo Moments APPµÄElasticsearchÊý¾Ý¿â¶³öÁËÊýǧ¸öÓ¤¶ùµÄÕÕÆ¬ºÍÊÓÆµÒÔ¼°ÖÁÉÙ80Íò¸öµç×ÓÓʼþµØÖ·¡£¸ÃÊý¾Ý¿âÊôÓÚPeekaboo MomentsµÄ¿ª·¢ÉÌBithouse£¬Êý¾Ý¿âÖдæÓÐ7000Íò¸öÈÕÖ¾Îļþ¡£³ýÁËÓ¤¶ùµÄÊÓÆµºÍÕÕÆ¬±í£¬¸ÃÊý¾Ý¿â»¹Ô̺¬Ó¤¶ùµÄµ®ÉúÈÕÆÚ¡¢Éí³¤ºÍÌå³ÁÒÔ¼°¾¶ÈºÍγ¶ÈµØÎ»Êý¾Ý¡£´Ë±í£¬Ð¹Â¶µÄÊý¾ÝÒÉΪPeekaboo MomentsµÄFacebook APIÃÜÔ¿£¬¸¸Ä¸¿ÉʹÓøÃÃÜÔ¿½«ÕÕÆ¬µÈ°ä²¼µ½Facebook¡£Æ¾¾ÝEhrlichµÄ˵·¨£¬¹¥»÷Õß¿ÉÄÜ»áÀûÓÃÕâЩÃÜÔ¿À´½Ó¼ûÓû§FacebookÒ³ÃæÉϵÄÄÚÈÝ¡£BithouseÔÚ½Óµ½»ã±¨ºóѸËÙ¶Ô·þÎñÆ÷½øÐÐÁ˱£»¤¡£
ÔÎÄÁ´½Ó£º
https://hotforsecurity.bitdefender.com/blog/peekaboo-moments-app-left-baby-videos-photos-and-800000-users-email-addresses-exposed-on-the-internet-22067.html
5.¼ÓÄôóÍøÉÏÒ©µêPlanetDrugsDirectй¶²¿Ãſͻ§Ö§¸¶ÐÅÏ¢
¼ÓÄôóÍøÉÏÒ©µêPlanetDrugsDirectÔÚͨ¹ýµç×ÓÓʼþ֪ͨ¿Í»§ÆäÓ×ÎҺͲÆÕþÐÅÏ¢Êܵ½Êý¾Ýй¶ÊÂÎñµÄÓ°Ïì¡£PlanetDrugsDirect³Æ×Ô¼ºÎª¿Í»§Ìṩ»ñµÃ´¦·½Ò©ºÍ·Ç´¦·½Ò©µÄ»úÓö£¬Æä¿Í»§ÊýÁ¿Ô¼Îª40Íò¡£Æ¾¾Ý¸ÃÒ©µêµÄ֪ͨ£¬¿ÉÄÜй¶µÄÊý¾ÝÔ̺¬¿Í»§µÄÐÕÃû¡¢×¡Ö·¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂëÒÔ¼°´¦·½µÄÒ½ÁÆÐÅÏ¢ºÍ¸¶¿îÐÅÏ¢£¬µ«Ã»ÓÐÖ¤¾ÝÅú×¢Óû§µÄÃÜÂëÊܵ½ÇÖº¦¡£PlanetDrugsDirect»¹Ö¸³ö¸ÃÊÂÎñĿǰÔÚµ÷²éÖУ¬½«¾¡¿ìÌṩ¸ü¶à¾ßÌåÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/online-pharmacy-planetdrugsdirect-discloses-security-breach/
6.Êý°Ù¸öҽѧ³ÉÏñϵͳÔÚÍøÉ϶³öÁËÊý°ÙÍò»¼ÕßµÄÊý¾Ý
µÂ¹ú°²È«³§ÉÌGreenbone³ÆÊý°Ù¸ö¿É¹«¿ª½Ó¼ûµÄҽѧ³ÉÏñϵͳÔÚ»¥ÁªÍøÉ϶³öÁËÈ«ÇòÊý°ÙÍò»¼ÕßµÄÊý¾Ý¡£¸ÃÏî×êÑгÁµã·ÖÎöÔÚÍøÉ϶³öµÄҽѧͼƬ´æµµºÍͨѶϵͳ£¨PACS£©£¬ÔÚËùÓÐÊÜ·ÖÎöµÄPACS·þÎñÆ÷ÖУ¬Óн«½ü1/4µÄϵͳ½«Êý¾Ý¶³öÔÚ»¥ÁªÍøÉÏ¡£¾ßÌåÀ´Ëµ£¬ÔÚ2019Äê7ÔÂÖÁ2019Äê9ÔÂÖ®¼ä·ÖÎöµÄ2300¸öϵͳÖУ¬ÓÐ590¸ö¿É´ÓInternet½Ó¼û²¢ÇÒδÉèÃÜÂ룬¹²Óг¬¹ý2450ÍòÌõ»¼ÕßÊý¾Ý¶³ö£¬ÔÚ11Ô·ݵÄ×êÑÐÖУ¬¸Ã¹«Ë¾Ð¹Â©ÓÐ3500ÍòÌõ»¼Õ߼ͼ¿É¹«¿ª½Ó¼û¡£ÔÚ9ÔÂÖÁ11ÔÂÖ®¼ä£¬Ô̺¬Ò½ÁÆÍ¼ÏñµÄ¶³ö»¼Õ߼ͼÊýÁ¿ÒÑ´Ó440ÍòÔö³¤ÁËÒ»±¶£¬´ïµ½900Íò¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/unprotected-medical-systems-expose-data-millions-patients


¾©¹«Íø°²±¸11010802024551ºÅ