Zoom¶à¿îÈí¼þÔ¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-07-17

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-13567 £¬£¬£¬£¬£¬ £¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬£¬£¬£¬£¬ £¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾

MacµÄZoom Client 4.4.53932.0709֮ǰ°æ±¾


·ì϶¸ÅÊö


ZoomÊÇÆóÒµÊÓÆµÍ¨Ñ¶ÁìÓòµÄ¸¨µ¼Õß £¬£¬£¬£¬£¬ £¬£¬ÊÇÊÓÆµºÍÒôƵ»áÒé £¬£¬£¬£¬£¬ £¬£¬Ì¸ÌìºÍÍøÂç×êÑлá×îÊÜ»¶Ó­ºÍ×î¿¿µÃסµÄÔÆÆ½Ì¨Ö®Ò»¡£¡£¡£¡£¡£ ¡£¡£


ÔÚ7ÔÂ10ÈÕ¹ãÊÜ»¶Ó­ÇÒ¿í·ºÊ¹ÓõÄZoomÊÓÆµ»áÒéÈí¼þÖÐÅû¶ÒþÖÔ·ì϶CVE-2019-13450µÄ»ìÂҺͷ¢¼±»¹Ã»ÓÐʵÏÖ¡£¡£¡£¡£¡£ ¡£¡£Èí¼þ±¾µØ×°ÖõÄweb·þÎñÆ÷²»½öÔÊÐíÈκÎÍøÕ¾´ò¿ªÄúµÄÉè±¸ÍøÂçÉãÏñÍ· £¬£¬£¬£¬£¬ £¬£¬²¢ÇÒ»¹Äܹ»ÈúڿÍÔ¶³ÌÆëÈ«½ÚÔìÄúµÄApple MacÍÆËã»ú¡£¡£¡£¡£¡£ ¡£¡£


¾Ý±¨Â· £¬£¬£¬£¬£¬ £¬£¬ÓÃÓÚmacOSµÄ»ùÓÚÔÆµÄZoom»áÒéÆ½Ì¨Ò²±»·¢ÏÖÈÝÒ×Êܵ½ÁíÒ»¸öÑϳÁ·ì϶£¨CVE-2019-13567£©µÄÓ°Ïì £¬£¬£¬£¬£¬ £¬£¬¸Ã·ì϶¿ÉÄÜÔÊÐíÔ¶³Ì¹¥»÷ÕßÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£ ¡£¡£


ÕâÁ½¸ö·ì϶¶¼Ô´ÓÚÒ»¸öÓÐÕùÒéµÄ±¾µØWeb·þÎñÆ÷ £¬£¬£¬£¬£¬ £¬£¬ÔÚ¶Ë¿Ú19421ÉÏÔËÐÐ £¬£¬£¬£¬£¬ £¬£¬Zoom¿Í»§¶Ë×°ÖÃÔÚÓû§µÄÍÆËã»úÉÏÒÔÌṩµã»÷²ÎÓëÖ°ÄÜ¡£¡£¡£¡£¡£ ¡£¡£°²È«×êÑÐÈËԱǿµ÷µÄÖØÒªÊÇÁ½¸öÎÊÌ⣺Ê×ÏÈ £¬£¬£¬£¬£¬ £¬£¬±¾µØ·þÎñÆ÷¡°²»°²È«¡±Í¨¹ýHTTP½Ó¹ÜºÅÁî £¬£¬£¬£¬£¬ £¬£¬ÔÊÐíÈκÎÍøÕ¾ÓëÖ®½»»¥ £¬£¬£¬£¬£¬ £¬£¬Æä´Î £¬£¬£¬£¬£¬ £¬£¬µ±Óû§´ÓÆäϵͳÖÐɾ³ýZoom¿Í»§¶Ëʱ £¬£¬£¬£¬£¬ £¬£¬Ëü²»»á±»Ð¶ÔØ £¬£¬£¬£¬£¬ £¬£¬ÈÃËûÃÇʼÖÕ´àÈõ¡£¡£¡£¡£¡£ ¡£¡£


ÏÂÃæÁгöµÄZoomÈí¼þ¹²ÓÐ10¸ö¸ÄÃû°æ±¾ £¬£¬£¬£¬£¬ £¬£¬¿ÉÔÚÊг¡ÉÏÂòµ½¡£¡£¡£¡£¡£ ¡£¡£ËùÓÐÕâЩÊÓÆµ»áÒéÈí¼þ¶¼ÔÚ¹¤×÷ £¬£¬£¬£¬£¬ £¬£¬²¢Ô̺¬Ò»ÑùµÄ·ì϶ £¬£¬£¬£¬£¬ £¬£¬Ê¹Óû§Ò²Ãæ¶ÔÔ¶³ÌºÚ¿Í¹¥»÷µÄ·çÏÕ£º


RingCentral
Zhumu
Telus Meetings
BT Cloud Phone Meetings
Office Suite HD Meeting
AT&T Video Meetings
BizConf
Huihui
UMeeting

Zoom CN


AppleÒÑÍÆËÍÁËËùÓÐmacOSÓû§µÄ¸üР£¬£¬£¬£¬£¬ £¬£¬×Ô¶¯É¾³ýZoom Web·þÎñÆ÷¶øÎÞÐèÈκÎÓû§½»»¥¡£¡£¡£¡£¡£ ¡£¡£


·ì϶ÑéÖ¤


POCÊÓÆµ£º

https://twitter.com/karanlyons/status/1150774640899317760¡£¡£¡£¡£¡£ ¡£¡£


½¨¸´½¨Òé


Zoom½¨²¹ÁË·ì϶ £¬£¬£¬£¬£¬ £¬£¬Çë¸üÐÂÖÁZoom client version 4.4.53932.0709£ºhttps://zoom.us/download¡£¡£¡£¡£¡£ ¡£¡£

RingCentral½¨²¹ÁË·ì϶ £¬£¬£¬£¬£¬ £¬£¬Çë¸üÐÂÖÁRingCentral Meetings MacOS app v7.0.151508.0712£ºhttps://support.ringcentral.com/s/article/11201-Meetings-Security-Advisory?language=en_US¡£¡£¡£¡£¡£ ¡£¡£


»º½â´ëÊ©£º

½¨ÒéÓû§Í¨¹ýÔËÐÐGitHubÉϵÄ×êÑÐÈËÔ±ÌṩµÄºÅÁîÊÖ¶¯É¾³ý°µ²ØµÄWeb·þÎñÆ÷£ºhttps://gist.github.com/karanlyons/1fde1c63bd7bb809b04323be3f519f7e¡£¡£¡£¡£¡£ ¡£¡£


²Î¿¼Á´½Ó


https://thehackernews.com/2019/07/zoom-ringcentral-vulnerabilities.html 
https://thehackernews.com/2019/07/zoom-video-conferencing-hacking.html