ÊÔÓÃAppÐ¶ÔØºóÖ±½Ó¿Û·Ñ  £¬È«Çò½ü6ÒÚAndroidÓû§ÖÐÕУ»Î¢Èí°ä²¼1ÔÂOffice°²È«¸üР £¬½¨¸´3¸öRCE·ì϶

°ä²¼¹¦·ò 2020-01-17


1.ÊÔÓÃAppÐ¶ÔØºóÖ±½Ó¿Û·Ñ  £¬È«Çò½ü6ÒÚAndroidÓû§ÖÐÕÐ


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Sophos°²È«×êÑÐÈËÔ±·¢ÏÖÁËÒ»×éеÄfleeceware APP  £¬ÕâЩAPPÒѾ­±»³¬¹ý6ÒÚAndroidÓû§ÏÂÔØ×°Öá£fleecewareÊÇÖ¸¹È¸èPlayÉ̵êÖдæÔÚµÄÒ»ÖÖÐÂÐͽðÈÚڲƭÐÐΪ  £¬ÕâЩAPPÀÄÓÃAndroidÀûÓõÄÊÔÓÃÆÚÖ°ÄÜÏòÓû§ÊÕ·Ñ¡£Ä¬ÈÏÇé¿öÏÂAndroidÓû§ÔÚ×¢²áʹÆ÷ÓµÓÐÊÔÓÃÆÚµÄAPPʱ±ØÐëÊÖ¶¯È¡µÞÊÔÓà  £¬È»¶ø´óÎÞÊýÓû§Ö»ÊÇÔÚ²»Ï²»¶µÄʱ³½Ð¶ÔØAPP  £¬¾ø´óÎÞÊý¿ª·¢Õß½«ÕâÖÖÐ¶ÔØÐÐΪÊÓΪȡµÞÊÔÓà  £¬µ«Ò»Ð©¿ª·¢ÕßÔÚÓû§Ð¶ÔغóûÓÐÈ¡µÞÊÔÓò¢ÇÒ³ÖÐøÊÕ·Ñ¡£Sophos×î³õ·¢ÏÖµÄ24¸öAPPÔ̺¬¶þάÂëɨÃèÆ÷¡¢ÍÆËãÆ÷µÈ  £¬ËüÃÇÒÔÕâÖÖ·½Ê½ÏòÓû§ÊÕȡÿÄê100ÃÀÔªµ½240ÃÀÔªµÄ¶©ÔÄÓöÈ¡£ÔÚ½üÈÕ°ä²¼µÄÒ»·Ý»ã±¨ÖÐ  £¬Sophos·¢ÏÖÁËÁí±í25¸ö´ËÀàAPP  £¬Æä×Ü×°ÖÃÁ¿³¬¹ý6ÒÚ  £¬ÆëÈ«µÄAPPÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£


  Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/more-than-600-million-users-installed-android-fleeceware-apps-from-the-play-store/


2.΢Èí°ä²¼1ÔÂOffice°²È«¸üР £¬½¨¸´3¸öRCE·ì϶


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


΢ÈíÔÚ1ÔÂOffice°²È«¸üÐÂÖÐΪ5¸ö·ÖÆçµÄ²úÆ·°ä²¼ÁË×ܹ²7¸ö°²È«¸üкÍ3¸öÀۼƸüР £¬ÆäÖÐ6¸ö¸üÐÂÓëÔ¶³Ì´úÂëÖ´Ðзì϶ÓйØ¡£ÕâЩRCE·ì϶±»¸ú×ÙΪCVE-2020-0650¡¢CVE-2020-0651ºÍCVE-2020-0652  £¬ÊÜÓ°ÏìµÄ²úÆ·Ô̺¬Office 2016¡¢Office 2013¡¢Office 2010¡¢Excel 2016¡¢Excel 2013ºÍExcel 2010¡£´Ë±í±»¸ú×ÙΪCVE-2020-0647µÄÁíÒ»¸ö·ì϶ÊÇÓ°ÏìOffice Online ServerµÄºýŪ·ì϶  £¬ËüÊÇÓÉ¿çÓòͨѶÖеÄԭʼÑéÖ¤²»ÕýÈ·ÒýÆðµÄ  £¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚÊÜÓ°ÏìµÄϵͳÉϽøÐпçÓò¹¥»÷¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-office-january-security-updates-fix-code-execution-bugs/


3.VMware°ä²¼VMware Tools 11  £¬½¨¸´10°æ±¾ÖеÄLPE·ì϶


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


VMwareÒѰ䲼VMware Tools 11.0.0  £¬½¨¸´Á˰汾10.xyÖеı¾µØÌáȨ·ì϶£¨CVE-2020-3941£©¡£¸Ã·ì϶±»¹éÀàΪ¾ºÕùǰÌá·ì϶  £¬¹¥»÷Õß¿ÉÄÜÀûÓô˷ì϶ÔÚÐé¹¹»úÖÐÌáÉýÌØÈ¨¡£¸Ã·ì϶µÄCVSSÆÀ·ÖΪ7.8·Ö¡£´Ë±í  £¬VMware»¹½¨¸´ÁËWorkspace ONE SDKÖеÄÐÅϢй¶·ì϶£¨CVE-2020-3940£©  £¬¸Ã·ì϶ӰÏìÁËÓйصÄiOSºÍAndroid APP  £¬Ô̺¬Workspace ONE Boxer¡¢Content¡¢Intelligent Hub¡¢Notebook¡¢People¡¢PIV-D¡¢WebÒÔ¼°ºÏÓÃÓÚApache CordovaºÍXamarinµÄSDK²å¼þ¡£Æ¾¾Ý°²È«²¼¸æ  £¬ÈôÊÇÆôÓÃÁËSSL Pinning  £¬ÔòÔÚÊÜÓ°ÏìµÄÒÆ¶¯APPºÍWorkspace ONE UEMÉ豸·þÎñÖ®¼äµÄÖÐÑëÈË£¨MITM£©¹¥»÷Õß¿ÉÄܲ¶»ñ´«ÊäÖеÄÃô¸ÐÊý¾Ý¡£


 Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/96446/security/vmware-tools-and-workspace-one-sdk-flaws.html


4.Peekaboo MomentsÒâ±íй¶80ÍòÓû§µÄÓÊÏäÐÅÏ¢


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


°²È«×êÑÐÔ±Dan Ehrlich·¢ÏÖPeekaboo Moments APPµÄElasticsearchÊý¾Ý¿â¶³öÁËÊýǧ¸öÓ¤¶ùµÄÕÕÆ¬ºÍÊÓÆµÒÔ¼°ÖÁÉÙ80Íò¸öµç×ÓÓʼþµØÖ·¡£¸ÃÊý¾Ý¿âÊôÓÚPeekaboo MomentsµÄ¿ª·¢ÉÌBithouse  £¬Êý¾Ý¿âÖдæÓÐ7000Íò¸öÈÕÖ¾Îļþ¡£³ýÁËÓ¤¶ùµÄÊÓÆµºÍÕÕÆ¬±í  £¬¸ÃÊý¾Ý¿â»¹Ô̺¬Ó¤¶ùµÄµ®ÉúÈÕÆÚ¡¢Éí³¤ºÍÌå³ÁÒÔ¼°¾­¶ÈºÍγ¶ÈµØÎ»Êý¾Ý¡£´Ë±í  £¬Ð¹Â¶µÄÊý¾ÝÒÉΪPeekaboo MomentsµÄFacebook APIÃÜÔ¿  £¬¸¸Ä¸¿ÉʹÓøÃÃÜÔ¿½«ÕÕÆ¬µÈ°ä²¼µ½Facebook¡£Æ¾¾ÝEhrlichµÄ˵·¨  £¬¹¥»÷Õß¿ÉÄÜ»áÀûÓÃÕâЩÃÜÔ¿À´½Ó¼ûÓû§FacebookÒ³ÃæÉϵÄÄÚÈÝ¡£BithouseÔÚ½Óµ½»ã±¨ºóѸËÙ¶Ô·þÎñÆ÷½øÐÐÁ˱£»¤¡£


 Ô­ÎÄÁ´½Ó£º

https://hotforsecurity.bitdefender.com/blog/peekaboo-moments-app-left-baby-videos-photos-and-800000-users-email-addresses-exposed-on-the-internet-22067.html


5.¼ÓÄôóÍøÉÏÒ©µêPlanetDrugsDirectй¶²¿Ãſͻ§Ö§¸¶ÐÅÏ¢


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¼ÓÄôóÍøÉÏÒ©µêPlanetDrugsDirectÔÚͨ¹ýµç×ÓÓʼþ֪ͨ¿Í»§ÆäÓ×ÎҺͲÆÕþÐÅÏ¢Êܵ½Êý¾Ýй¶ÊÂÎñµÄÓ°Ïì¡£PlanetDrugsDirect³Æ×Ô¼ºÎª¿Í»§Ìṩ»ñµÃ´¦·½Ò©ºÍ·Ç´¦·½Ò©µÄ»úÓö  £¬Æä¿Í»§ÊýÁ¿Ô¼Îª40Íò¡£Æ¾¾Ý¸ÃÒ©µêµÄ֪ͨ  £¬¿ÉÄÜй¶µÄÊý¾ÝÔ̺¬¿Í»§µÄÐÕÃû¡¢×¡Ö·¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂëÒÔ¼°´¦·½µÄÒ½ÁÆÐÅÏ¢ºÍ¸¶¿îÐÅÏ¢  £¬µ«Ã»ÓÐÖ¤¾ÝÅú×¢Óû§µÄÃÜÂëÊܵ½ÇÖº¦¡£PlanetDrugsDirect»¹Ö¸³ö¸ÃÊÂÎñĿǰÔÚµ÷²éÖÐ  £¬½«¾¡¿ìÌṩ¸ü¶à¾ßÌåÐÅÏ¢¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/online-pharmacy-planetdrugsdirect-discloses-security-breach/


6.Êý°Ù¸öҽѧ³ÉÏñϵͳÔÚÍøÉ϶³öÁËÊý°ÙÍò»¼ÕßµÄÊý¾Ý


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


µÂ¹ú°²È«³§ÉÌGreenbone³ÆÊý°Ù¸ö¿É¹«¿ª½Ó¼ûµÄҽѧ³ÉÏñϵͳÔÚ»¥ÁªÍøÉ϶³öÁËÈ«ÇòÊý°ÙÍò»¼ÕßµÄÊý¾Ý¡£¸ÃÏî×êÑгÁµã·ÖÎöÔÚÍøÉ϶³öµÄҽѧͼƬ´æµµºÍͨѶϵͳ£¨PACS£©  £¬ÔÚËùÓÐÊÜ·ÖÎöµÄPACS·þÎñÆ÷ÖÐ  £¬Óн«½ü1/4µÄϵͳ½«Êý¾Ý¶³öÔÚ»¥ÁªÍøÉÏ¡£¾ßÌåÀ´Ëµ  £¬ÔÚ2019Äê7ÔÂÖÁ2019Äê9ÔÂÖ®¼ä·ÖÎöµÄ2300¸öϵͳÖÐ  £¬ÓÐ590¸ö¿É´ÓInternet½Ó¼û²¢ÇÒδÉèÃÜÂë  £¬¹²Óг¬¹ý2450ÍòÌõ»¼ÕßÊý¾Ý¶³ö  £¬ÔÚ11Ô·ݵÄ×êÑÐÖÐ  £¬¸Ã¹«Ë¾Ð¹Â©ÓÐ3500ÍòÌõ»¼Õ߼ͼ¿É¹«¿ª½Ó¼û¡£ÔÚ9ÔÂÖÁ11ÔÂÖ®¼ä  £¬Ô̺¬Ò½ÁÆÍ¼ÏñµÄ¶³ö»¼Õ߼ͼÊýÁ¿ÒÑ´Ó440ÍòÔö³¤ÁËÒ»±¶  £¬´ïµ½900Íò¡£


 Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/unprotected-medical-systems-expose-data-millions-patients