ÊÔÓÃAppÐ¶ÔØºóÖ±½Ó¿Û·Ñ£¬£¬£¬£¬£¬È«Çò½ü6ÒÚAndroidÓû§ÖÐÕУ» £»£»£»£» £»£»£»Î¢Èí°ä²¼1ÔÂOffice°²È«¸üУ¬£¬£¬£¬£¬½¨¸´3¸öRCE·ì϶

°ä²¼¹¦·ò 2020-01-17


1.ÊÔÓÃAppÐ¶ÔØºóÖ±½Ó¿Û·Ñ£¬£¬£¬£¬£¬È«Çò½ü6ÒÚAndroidÓû§ÖÐÕÐ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Sophos°²È«×êÑÐÈËÔ±·¢ÏÖÁËÒ»×éеÄfleeceware APP£¬£¬£¬£¬£¬ÕâЩAPPÒѾ­±»³¬¹ý6ÒÚAndroidÓû§ÏÂÔØ×°Öᣡ£¡£¡£¡£ ¡£¡£¡£fleecewareÊÇÖ¸¹È¸èPlayÉ̵êÖдæÔÚµÄÒ»ÖÖÐÂÐͽðÈÚڲƭÐÐΪ£¬£¬£¬£¬£¬ÕâЩAPPÀÄÓÃAndroidÀûÓõÄÊÔÓÃÆÚÖ°ÄÜÏòÓû§ÊÕ·Ñ¡£¡£¡£¡£¡£ ¡£¡£¡£Ä¬ÈÏÇé¿öÏÂAndroidÓû§ÔÚ×¢²áʹÆ÷ÓµÓÐÊÔÓÃÆÚµÄAPPʱ±ØÐëÊÖ¶¯È¡µÞÊÔÓ㬣¬£¬£¬£¬È»¶ø´óÎÞÊýÓû§Ö»ÊÇÔÚ²»Ï²»¶µÄʱ³½Ð¶ÔØAPP£¬£¬£¬£¬£¬¾ø´óÎÞÊý¿ª·¢Õß½«ÕâÖÖÐ¶ÔØÐÐΪÊÓΪȡµÞÊÔÓ㬣¬£¬£¬£¬µ«Ò»Ð©¿ª·¢ÕßÔÚÓû§Ð¶ÔغóûÓÐÈ¡µÞÊÔÓò¢ÇÒ³ÖÐøÊÕ·Ñ¡£¡£¡£¡£¡£ ¡£¡£¡£Sophos×î³õ·¢ÏÖµÄ24¸öAPPÔ̺¬¶þάÂëɨÃèÆ÷¡¢ÍÆËãÆ÷µÈ£¬£¬£¬£¬£¬ËüÃÇÒÔÕâÖÖ·½Ê½ÏòÓû§ÊÕȡÿÄê100ÃÀÔªµ½240ÃÀÔªµÄ¶©ÔÄÓöȡ£¡£¡£¡£¡£ ¡£¡£¡£ÔÚ½üÈÕ°ä²¼µÄÒ»·Ý»ã±¨ÖУ¬£¬£¬£¬£¬Sophos·¢ÏÖÁËÁí±í25¸ö´ËÀàAPP£¬£¬£¬£¬£¬Æä×Ü×°ÖÃÁ¿³¬¹ý6ÒÚ£¬£¬£¬£¬£¬ÆëÈ«µÄAPPÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£ ¡£¡£¡£


  Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/more-than-600-million-users-installed-android-fleeceware-apps-from-the-play-store/


2.΢Èí°ä²¼1ÔÂOffice°²È«¸üУ¬£¬£¬£¬£¬½¨¸´3¸öRCE·ì϶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


΢ÈíÔÚ1ÔÂOffice°²È«¸üÐÂÖÐΪ5¸ö·ÖÆçµÄ²úÆ·°ä²¼ÁË×ܹ²7¸ö°²È«¸üкÍ3¸öÀۼƸüУ¬£¬£¬£¬£¬ÆäÖÐ6¸ö¸üÐÂÓëÔ¶³Ì´úÂëÖ´Ðзì϶Óйء£¡£¡£¡£¡£ ¡£¡£¡£ÕâЩRCE·ì϶±»¸ú×ÙΪCVE-2020-0650¡¢CVE-2020-0651ºÍCVE-2020-0652£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄ²úÆ·Ô̺¬Office 2016¡¢Office 2013¡¢Office 2010¡¢Excel 2016¡¢Excel 2013ºÍExcel 2010¡£¡£¡£¡£¡£ ¡£¡£¡£´Ë±í±»¸ú×ÙΪCVE-2020-0647µÄÁíÒ»¸ö·ì϶ÊÇÓ°ÏìOffice Online ServerµÄºýŪ·ì϶£¬£¬£¬£¬£¬ËüÊÇÓÉ¿çÓòͨѶÖеÄԭʼÑéÖ¤²»ÕýÈ·ÒýÆðµÄ£¬£¬£¬£¬£¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚÊÜÓ°ÏìµÄϵͳÉϽøÐпçÓò¹¥»÷¡£¡£¡£¡£¡£ ¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-office-january-security-updates-fix-code-execution-bugs/


3.VMware°ä²¼VMware Tools 11£¬£¬£¬£¬£¬½¨¸´10°æ±¾ÖеÄLPE·ì϶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


VMwareÒѰ䲼VMware Tools 11.0.0£¬£¬£¬£¬£¬½¨¸´Á˰汾10.xyÖеı¾µØÌáȨ·ì϶£¨CVE-2020-3941£©¡£¡£¡£¡£¡£ ¡£¡£¡£¸Ã·ì϶±»¹éÀàΪ¾ºÕùǰÌá·ì϶£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜÀûÓô˷ì϶ÔÚÐé¹¹»úÖÐÌáÉýÌØÈ¨¡£¡£¡£¡£¡£ ¡£¡£¡£¸Ã·ì϶µÄCVSSÆÀ·ÖΪ7.8·Ö¡£¡£¡£¡£¡£ ¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬VMware»¹½¨¸´ÁËWorkspace ONE SDKÖеÄÐÅϢй¶·ì϶£¨CVE-2020-3940£©£¬£¬£¬£¬£¬¸Ã·ì϶ӰÏìÁËÓйصÄiOSºÍAndroid APP£¬£¬£¬£¬£¬Ô̺¬Workspace ONE Boxer¡¢Content¡¢Intelligent Hub¡¢Notebook¡¢People¡¢PIV-D¡¢WebÒÔ¼°ºÏÓÃÓÚApache CordovaºÍXamarinµÄSDK²å¼þ¡£¡£¡£¡£¡£ ¡£¡£¡£Æ¾¾Ý°²È«²¼¸æ£¬£¬£¬£¬£¬ÈôÊÇÆôÓÃÁËSSL Pinning£¬£¬£¬£¬£¬ÔòÔÚÊÜÓ°ÏìµÄÒÆ¶¯APPºÍWorkspace ONE UEMÉ豸·þÎñÖ®¼äµÄÖÐÑëÈË£¨MITM£©¹¥»÷Õß¿ÉÄܲ¶»ñ´«ÊäÖеÄÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£ ¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/96446/security/vmware-tools-and-workspace-one-sdk-flaws.html


4.Peekaboo MomentsÒâ±íй¶80ÍòÓû§µÄÓÊÏäÐÅÏ¢


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


°²È«×êÑÐÔ±Dan Ehrlich·¢ÏÖPeekaboo Moments APPµÄElasticsearchÊý¾Ý¿â¶³öÁËÊýǧ¸öÓ¤¶ùµÄÕÕÆ¬ºÍÊÓÆµÒÔ¼°ÖÁÉÙ80Íò¸öµç×ÓÓʼþµØÖ·¡£¡£¡£¡£¡£ ¡£¡£¡£¸ÃÊý¾Ý¿âÊôÓÚPeekaboo MomentsµÄ¿ª·¢ÉÌBithouse£¬£¬£¬£¬£¬Êý¾Ý¿âÖдæÓÐ7000Íò¸öÈÕÖ¾Îļþ¡£¡£¡£¡£¡£ ¡£¡£¡£³ýÁËÓ¤¶ùµÄÊÓÆµºÍÕÕÆ¬±í£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿â»¹Ô̺¬Ó¤¶ùµÄµ®ÉúÈÕÆÚ¡¢Éí³¤ºÍÌå³ÁÒÔ¼°¾­¶ÈºÍγ¶ÈµØÎ»Êý¾Ý¡£¡£¡£¡£¡£ ¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬Ð¹Â¶µÄÊý¾ÝÒÉΪPeekaboo MomentsµÄFacebook APIÃÜÔ¿£¬£¬£¬£¬£¬¸¸Ä¸¿ÉʹÓøÃÃÜÔ¿½«ÕÕÆ¬µÈ°ä²¼µ½Facebook¡£¡£¡£¡£¡£ ¡£¡£¡£Æ¾¾ÝEhrlichµÄ˵·¨£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜ»áÀûÓÃÕâЩÃÜÔ¿À´½Ó¼ûÓû§FacebookÒ³ÃæÉϵÄÄÚÈÝ¡£¡£¡£¡£¡£ ¡£¡£¡£BithouseÔÚ½Óµ½»ã±¨ºóѸËÙ¶Ô·þÎñÆ÷½øÐÐÁ˱£» £»£»£»£» £»£»£»¤¡£¡£¡£¡£¡£ ¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://hotforsecurity.bitdefender.com/blog/peekaboo-moments-app-left-baby-videos-photos-and-800000-users-email-addresses-exposed-on-the-internet-22067.html


5.¼ÓÄôóÍøÉÏÒ©µêPlanetDrugsDirectй¶²¿Ãſͻ§Ö§¸¶ÐÅÏ¢


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¼ÓÄôóÍøÉÏÒ©µêPlanetDrugsDirectÔÚͨ¹ýµç×ÓÓʼþ֪ͨ¿Í»§ÆäÓ×ÎҺͲÆÕþÐÅÏ¢Êܵ½Êý¾Ýй¶ÊÂÎñµÄÓ°Ïì¡£¡£¡£¡£¡£ ¡£¡£¡£PlanetDrugsDirect³Æ×Ô¼ºÎª¿Í»§Ìṩ»ñµÃ´¦·½Ò©ºÍ·Ç´¦·½Ò©µÄ»úÓö£¬£¬£¬£¬£¬Æä¿Í»§ÊýÁ¿Ô¼Îª40Íò¡£¡£¡£¡£¡£ ¡£¡£¡£Æ¾¾Ý¸ÃÒ©µêµÄ֪ͨ£¬£¬£¬£¬£¬¿ÉÄÜй¶µÄÊý¾ÝÔ̺¬¿Í»§µÄÐÕÃû¡¢×¡Ö·¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂëÒÔ¼°´¦·½µÄÒ½ÁÆÐÅÏ¢ºÍ¸¶¿îÐÅÏ¢£¬£¬£¬£¬£¬µ«Ã»ÓÐÖ¤¾ÝÅú×¢Óû§µÄÃÜÂëÊܵ½ÇÖº¦¡£¡£¡£¡£¡£ ¡£¡£¡£PlanetDrugsDirect»¹Ö¸³ö¸ÃÊÂÎñĿǰÔÚµ÷²éÖУ¬£¬£¬£¬£¬½«¾¡¿ìÌṩ¸ü¶à¾ßÌåÐÅÏ¢¡£¡£¡£¡£¡£ ¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/online-pharmacy-planetdrugsdirect-discloses-security-breach/


6.Êý°Ù¸öҽѧ³ÉÏñϵͳÔÚÍøÉ϶³öÁËÊý°ÙÍò»¼ÕßµÄÊý¾Ý


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


µÂ¹ú°²È«³§ÉÌGreenbone³ÆÊý°Ù¸ö¿É¹«¿ª½Ó¼ûµÄҽѧ³ÉÏñϵͳÔÚ»¥ÁªÍøÉ϶³öÁËÈ«ÇòÊý°ÙÍò»¼ÕßµÄÊý¾Ý¡£¡£¡£¡£¡£ ¡£¡£¡£¸ÃÏî×êÑгÁµã·ÖÎöÔÚÍøÉ϶³öµÄҽѧͼƬ´æµµºÍͨѶϵͳ£¨PACS£©£¬£¬£¬£¬£¬ÔÚËùÓÐÊÜ·ÖÎöµÄPACS·þÎñÆ÷ÖУ¬£¬£¬£¬£¬Óн«½ü1/4µÄϵͳ½«Êý¾Ý¶³öÔÚ»¥ÁªÍøÉÏ¡£¡£¡£¡£¡£ ¡£¡£¡£¾ßÌåÀ´Ëµ£¬£¬£¬£¬£¬ÔÚ2019Äê7ÔÂÖÁ2019Äê9ÔÂÖ®¼ä·ÖÎöµÄ2300¸öϵͳÖУ¬£¬£¬£¬£¬ÓÐ590¸ö¿É´ÓInternet½Ó¼û²¢ÇÒδÉèÃÜÂ룬£¬£¬£¬£¬¹²Óг¬¹ý2450ÍòÌõ»¼ÕßÊý¾Ý¶³ö£¬£¬£¬£¬£¬ÔÚ11Ô·ݵÄ×êÑÐÖУ¬£¬£¬£¬£¬¸Ã¹«Ë¾Ð¹Â©ÓÐ3500ÍòÌõ»¼Õ߼ͼ¿É¹«¿ª½Ó¼û¡£¡£¡£¡£¡£ ¡£¡£¡£ÔÚ9ÔÂÖÁ11ÔÂÖ®¼ä£¬£¬£¬£¬£¬Ô̺¬Ò½ÁÆÍ¼ÏñµÄ¶³ö»¼Õ߼ͼÊýÁ¿ÒÑ´Ó440ÍòÔö³¤ÁËÒ»±¶£¬£¬£¬£¬£¬´ïµ½900Íò¡£¡£¡£¡£¡£ ¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/unprotected-medical-systems-expose-data-millions-patients