Chrome¡¢EdgeºÍSafari¾ùÔÚÌ츮±­Öб»¹¥ÆÆ£»£»£»£»£»£»Â·Ò×˹°²ÄÇÖÝÕþ¸®ÔâÀÕË÷Èí¼þ¹¥»÷

Ðû²¼Ê±¼ä 2019-11-19
1¡¢Î¢ÈíÐû²¼11ÔÂOfficeÇå¾²¸üР£¬£¬ £¬£¬£¬ÐÞ¸´¶à¸öÎó²î

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

΢ÈíÔÚ11ÔÂOfficeÇå¾²¸üÐÂÖÐΪ7¸ö²î±ðµÄ²úÆ·Ðû²¼ÁË17¸öÇå¾²¸üкÍ5¸öÀۼƸüР£¬£¬ £¬£¬£¬ÆäÖÐ15¸öÓëδÊÚȨµÄÐÅÏ¢»á¼ûÓйØ¡£¡£¡£¡£¡£Î¢ÈíÔÚ17¸öOfficeÇå¾²¸üÐÂÖÐÐÞ¸´ÁË6¸öÐÅϢй¶Îó²î £¬£¬ £¬£¬£¬°üÀ¨CVE-2019-1442¡¢CVE-2019-1443¡¢CVE-2019-1446¡¢CVE-2019-1448¡¢CVE-2019-1402ºÍCVE-2019-1409 £¬£¬ £¬£¬£¬ÊÜÓ°ÏìµÄ²úÆ·°üÀ¨Office 2010µ½Office 2016¡¢Excel 2010µ½Excel 2016¡¢SharePoint Server 2010µ½SharePoint Server 2019¡£¡£¡£¡£¡£ÁíÍâÁ½¸öÎó²î»¹°üÀ¨SharePoint Server 2019ÓïÑÔ°üºÍOffice OnlineЧÀÍÆ÷ÖеÄÇå¾²ÈÆ¹ýÎó²î£¨CVE-2019-1449ºÍCVE-2019-1457£©¡£¡£¡£¡£¡£ÍêÕûÎó²îÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-the-november-2019-security-updates-for-office/

2¡¢¹È¸èÐÞ¸´Gmail¶¯Ì¬µç×ÓÓʼþ¹¦Ð§ÖеÄXSSÎó²î


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


¹È¸èÐÞ¸´Gmail¶¯Ì¬µç×ÓÓʼþ¹¦Ð§ÖеÄXSSÎó²î £¬£¬ £¬£¬£¬Æ¾Ö¤Ñо¿Ö°Ô±µÄ±íÊö £¬£¬ £¬£¬£¬¸ÃÎó²îÊÇDOM Clobbering¹¥»÷µÄÒ»¸öµäµä·¶×Ó¡£¡£¡£¡£¡£¸ÃÎó²î±£´æÓÚAMP4Email£¨Ò²³ÆÎª¶¯Ì¬µç×ÓÓʼþ£©¹¦Ð§ÖÐ £¬£¬ £¬£¬£¬AMP4Email¾ßÓÐÒ»¸ö¹ýÂËXSSµÄÑé֤ϵͳ £¬£¬ £¬£¬£¬µ«Ñо¿Ö°Ô±·¢Ã÷±êÇ©ÖÐidµÄÊôÐÔÊDZ»ÔÊÐíµÄ¡£¡£¡£¡£¡£ÔÚAMP4EmailÖÐ £¬£¬ £¬£¬£¬idÊôÐÔµÄijЩֵÊܵ½ÏÞÖÆ £¬£¬ £¬£¬£¬¿ÉÊÇ £¬£¬ £¬£¬£¬ÔÚAMP_MODEÖÐÈôÊǸú¯ÊýʵÑé¼ÓÔØJSÎļþ £¬£¬ £¬£¬£¬Ôò¹ýʧ»áµ¼ÖÂ404 £¬£¬ £¬£¬£¬´Ó¶øÔÚЧ¹ûURLÖе¼Ö¡°Î´½ç˵¡±µÄ²¿·Ö¡£¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ý½«payloadдÈëwindow.testLocationÀ´¿ØÖÆURL¡£¡£¡£¡£¡£µ«ÔÚÏÖÕæÏàÐÎÖÐAMPµÄÄÚÈÝÇå¾²Õ½ÂÔ£¨CSP£©¹¦Ð§½«»á×èÖ¹´úÂë»ñµÃÖ´ÐС£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/google-patches-awesome-xss-vulnerability-in-gmail/

3¡¢Ó¡¶ÈÃÀױƽ̨Nykaa APIÎó²î̻¶½ü100ÍòÓû§Êý¾Ý

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

Ó¡¶ÈÃÀ×±ÁãÊÛÆ½Ì¨Nykaa FashionÒÑÐÞ¸´Ò»¸ö¿Éµ¼Ö½ü100Íò¿Í»§ÐÅϢй¶µÄÎó²î¡£¡£¡£¡£¡£ÕâÊÇÒ»¸öAPIÎó²î £¬£¬ £¬£¬£¬¹¥»÷Õߣ¨ÀýÈçºÚ¿Í»òµç»°ÍÆÏúÔ±£©¿ÉʹÓÃ×Ô¶¯»¯¾ç±¾»ñÈ¡Óû§Êý¾Ý £¬£¬ £¬£¬£¬°üÀ¨¶©µ¥ÏêϸÐÅÏ¢¡¢Óʼþ±êʶ¡¢ÐÕÃû¡¢µç»°ºÅÂëºÍµç×ÓÓʼþµØµã¡£¡£¡£¡£¡£NykaaÊ×ϯÊÖÒÕ¹ÙSanjay SuriÔÚÒ»·ÝÉùÃ÷ÖÐÌåÏÖ £¬£¬ £¬£¬£¬¸Ã¹«Ë¾ÒѾ­½â¾öÁ˸ÃÎÊÌâ²¢ÇÒûÓÐСÎÒ˽¼Ò»ò²ÆÎñÊý¾Ýй¶¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://economictimes.indiatimes.com/small-biz/startups/newsbuzz/nykaa-fixes-a-data-security-bug/articleshow/72101784.cms

4¡¢Chrome¡¢EdgeºÍSafari¾ùÔÚÌ츮±­Öб»¹¥ÆÆ


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ÔÚ11ÔÂ16ÈÕÖÁ17Èճɶ¼¾ÙÐеÄÌ츮±­ÉÏ £¬£¬ £¬£¬£¬Edge¡¢Chrome¡¢Safari¾ù±»²ÎÈüÕß¹¥ÆÆ £¬£¬ £¬£¬£¬ÆäËü±»¹¥ÆÆµÄ²úÆ·»¹°üÀ¨Office 365¡¢iOS¡¢Ð¡Ãס¢Vivo¡¢VirtualBox¡¢ÓÑѶ¿Æ¼¼µÄ·ÓÉÆ÷¡¢Adobe PDF ºÍ VMWare WorkstationµÈ¡£¡£¡£¡£¡£Õâ´Î´óÈüÉϹ²ÓÐ23Ö§²½¶Ó²ÎÈü £¬£¬ £¬£¬£¬ÈüÖÆÀàËÆÓÚPwn2Own £¬£¬ £¬£¬£¬¹²ÉèÖÃÁË100ÍòÃÀÔª½±½ð³Ø¡£¡£¡£¡£¡£ÔÚÕâ´ÎΪÆÚÁ½ÌìµÄ½ÇÖðÖÐ £¬£¬ £¬£¬£¬¹²ÓÐ20´Î¹¥»÷ʵÑé»ñµÃÀÖ³É £¬£¬ £¬£¬£¬²ÎÈüÕßÒ»¹²Ó®µÃÁË54.5ÍòÃÀÔªµÄ½±½ð¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/chrome-edge-safari-hacked-at-elite-chinese-hacking-contest/

5¡¢Ð´¹ÂڻÖ÷ÒªÕë¶ÔMicrosoft OfficeÖÎÀíÔ±


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


PhishLabs·¢Ã÷Ò»¸öÕë¶ÔMicrosoft Office 365ÖÎÀíÔ±µÄÍøÂç´¹Âڻ¡£¡£¡£¡£¡£¸Ã»î¶¯Ê¼ÓÚ´¹ÂÚÓʼþ £¬£¬ £¬£¬£¬Óʼþαװ³ÉÀ´×ÔMicrosoft £¬£¬ £¬£¬£¬²¢ÔÚ¶¥²¿ÏÔʾOffice 365µÄlogo £¬£¬ £¬£¬£¬µ«ËüÀ´×Ô²»ÊôÓÚMicrosoftµÄ¾­ÓÉÑéÖ¤µÄÓò¡£¡£¡£¡£¡£ÈôÊÇÊÕ¼þÈ˵ã»÷ÁËÓʼþÖеÄÁ´½Ó £¬£¬ £¬£¬£¬Ôò»á±»Öض¨Ïòµ½ÐéαµÄOffice 365µÇÂ¼Ò³Ãæ¡£¡£¡£¡£¡£¹¥»÷ÕßרÃÅÕë¶ÔÖÎÀíÔ±µÄƾ֤ £¬£¬ £¬£¬£¬Í¨¹ýÈëÇÖÖÎÀíÔ±ÕË»§ £¬£¬ £¬£¬£¬ËûÃÇ¿ÉÒÔDZÔڵؿØÖÆÓë¸ø¶¨Óò¹ØÁªµÄÆäËûµç×ÓÓʼþÕÊ»§ £¬£¬ £¬£¬£¬»¹¿ÉÒÔʹÓÃÖÎÀíÔ±ÕÊ»§µÄȨÏÞÀ´½¨ÉèÆäËûÕÊ»§ £¬£¬ £¬£¬£¬¾ÙÐиü¶à¶ñÒâ¹¥»÷¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.tripwire.com/state-of-security/security-data-protection/phishers-targeting-microsoft-office-365-admin-credentials/

6¡¢Â·Ò×˹°²ÄÇÖÝÕþ¸®ÔâÀÕË÷Èí¼þ¹¥»÷µ¼ÖÂÍ£°Ú


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


11ÔÂ18ÈÕ·Ò×˹°²ÄÇÖÝÕþ¸®Ôâµ½ÀÕË÷Èí¼þ¹¥»÷ £¬£¬ £¬£¬£¬°üÀ¨³µÁ¾ÖÎÀí°ì¹«ÊÒ¡¢ÎÀÉú²¿¡¢ÔËÊäÓëÉú³¤²¿ÔÚÄڵĶà¸öÖݲ¿·ÖÒÑÍ£°Ú¡£¡£¡£¡£¡£¸Ã¹¥»÷ÊÇÔÚ11µã±¨¸æµÄ £¬£¬ £¬£¬£¬´Ëǰ¸ÃÖÝÒÑÇ¿ÖÆ¹Ø±ÕÁËÓɸÃÖÝÔËÓªµÄÖÚ¶àÍøÕ¾¼°µç×ÓÓʼþЧÀÍ¡£¡£¡£¡£¡£¾ÝÍâµØÃ½Ì屨µÀ £¬£¬ £¬£¬£¬¸ÃÖݵĶà¸öЧÀÍ»ú¹¹¶¼Êܵ½×ÌÈÅ £¬£¬ £¬£¬£¬°üÀ¨79¸öÎÞа³µ°ì¹«ÊÒ¡£¡£¡£¡£¡£Öݳ¤John Bel EdwardsÌåÏÖËûÒѼ¤Éú·Ò×˹°²ÄÇÖݵÄÍøÂçÇå¾²ÍŶÓÀ´Ð­µ÷´Ë´Î¹¥»÷Ôì³ÉµÄÆÆË𡣡£¡£¡£¡£ÏÖÔÚÉв»ÇåÎú¸Ã¹¥»÷ÊÂÎñÖÐÀÕË÷Èí¼þµÄÀàÐÍ¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/louisiana-government-suffers-outage-due-to-ransomware-attack/