ÊÔÓÃAppÐ¶ÔØºóÖ±½Ó¿Û·Ñ£¬£¬£¬£¬È«Çò½ü6ÒÚAndroidÓû§ÖÐÕУ»£»£»£»Î¢ÈíÐû²¼1ÔÂOfficeÇå¾²¸üУ¬£¬£¬£¬ÐÞ¸´3¸öRCEÎó²î

Ðû²¼Ê±¼ä 2020-01-17


1.ÊÔÓÃAppÐ¶ÔØºóÖ±½Ó¿Û·Ñ£¬£¬£¬£¬È«Çò½ü6ÒÚAndroidÓû§ÖÐÕÐ


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


SophosÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»×éеÄfleeceware APP£¬£¬£¬£¬ÕâЩAPPÒѾ­±»Áè¼Ý6ÒÚAndroidÓû§ÏÂÔØ×°Öà ¡£¡£¡£¡£¡£fleecewareÊÇÖ¸¹È¸èPlayÊÐËÁÖб£´æµÄÒ»ÖÖÐÂÐͽðÈÚڲƭÐÐΪ£¬£¬£¬£¬ÕâЩAPPÀÄÓÃAndroidÓ¦ÓõÄÊÔÓÃÆÚ¹¦Ð§ÏòÓû§ÊÕ·Ñ ¡£¡£¡£¡£¡£Ä¬ÈÏÇéÐÎÏÂAndroidÓû§ÔÚ×¢²áʹÓþßÓÐÊÔÓÃÆÚµÄAPPʱ±ØÐèÊÖ¾Ù´ë·ÏÊÔÓ㬣¬£¬£¬È»¶ø´ó´ó¶¼Óû§Ö»ÊÇÔÚ²»Ï²»¶µÄʱ¼äÐ¶ÔØAPP£¬£¬£¬£¬¾ø´ó´ó¶¼¿ª·¢Õß½«ÕâÖÖÐ¶ÔØÐÐΪÊÓΪ×÷·ÏÊÔÓ㬣¬£¬£¬µ«Ò»Ð©¿ª·¢ÕßÔÚÓû§Ð¶ÔغóûÓÐ×÷·ÏÊÔÓò¢ÇÒ¼ÌÐøÊÕ·Ñ ¡£¡£¡£¡£¡£Sophos×î³õ·¢Ã÷µÄ24¸öAPP°üÀ¨¶þάÂëɨÃèÆ÷¡¢ÅÌËãÆ÷µÈ£¬£¬£¬£¬ËüÃÇÒÔÕâÖÖ·½·¨ÏòÓû§ÊÕȡÿÄê100ÃÀÔªµ½240ÃÀÔªµÄ¶©ÔÄÓÃ¶È ¡£¡£¡£¡£¡£ÔÚ¿ËÈÕÐû²¼µÄÒ»·Ý±¨¸æÖУ¬£¬£¬£¬Sophos·¢Ã÷ÁËÁíÍâ25¸ö´ËÀàAPP£¬£¬£¬£¬Æä×Ü×°ÖÃÁ¿Áè¼Ý6ÒÚ£¬£¬£¬£¬ÍêÕûµÄAPPÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó ¡£¡£¡£¡£¡£


  Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/more-than-600-million-users-installed-android-fleeceware-apps-from-the-play-store/


2.΢ÈíÐû²¼1ÔÂOfficeÇå¾²¸üУ¬£¬£¬£¬ÐÞ¸´3¸öRCEÎó²î


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


΢ÈíÔÚ1ÔÂOfficeÇå¾²¸üÐÂÖÐΪ5¸ö²î±ðµÄ²úÆ·Ðû²¼ÁË×ܹ²7¸öÇå¾²¸üкÍ3¸öÀۼƸüУ¬£¬£¬£¬ÆäÖÐ6¸ö¸üÐÂÓëÔ¶³Ì´úÂëÖ´ÐÐÎó²îÓÐ¹Ø ¡£¡£¡£¡£¡£ÕâЩRCEÎó²î±»¸ú×ÙΪCVE-2020-0650¡¢CVE-2020-0651ºÍCVE-2020-0652£¬£¬£¬£¬ÊÜÓ°ÏìµÄ²úÆ·°üÀ¨Office 2016¡¢Office 2013¡¢Office 2010¡¢Excel 2016¡¢Excel 2013ºÍExcel 2010 ¡£¡£¡£¡£¡£±ðµÄ±»¸ú×ÙΪCVE-2020-0647µÄÁíÒ»¸öÎó²îÊÇÓ°ÏìOffice Online ServerµÄÓÕÆ­Îó²î£¬£¬£¬£¬ËüÊÇÓÉ¿çÓòͨѶÖеÄԭʼÑéÖ¤²»×¼È·ÒýÆðµÄ£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÊÜÓ°ÏìµÄϵͳÉϾÙÐпçÓò¹¥»÷ ¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-office-january-security-updates-fix-code-execution-bugs/


3.VMwareÐû²¼VMware Tools 11£¬£¬£¬£¬ÐÞ¸´10°æ±¾ÖеÄLPEÎó²î


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


VMwareÒÑÐû²¼VMware Tools 11.0.0£¬£¬£¬£¬ÐÞ¸´Á˰汾10.xyÖеÄÍâµØÌáȨÎó²î£¨CVE-2020-3941£© ¡£¡£¡£¡£¡£¸ÃÎó²î±»¹éÀàΪ¾ºÕùÌõ¼þÎó²î£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜʹÓôËÎó²îÔÚÐéÄâ»úÖÐÌáÉýÌØÈ¨ ¡£¡£¡£¡£¡£¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.8·Ö ¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬VMware»¹ÐÞ¸´ÁËWorkspace ONE SDKÖеÄÐÅϢй¶Îó²î£¨CVE-2020-3940£©£¬£¬£¬£¬¸ÃÎó²îÓ°ÏìÁËÏà¹ØµÄiOSºÍAndroid APP£¬£¬£¬£¬°üÀ¨Workspace ONE Boxer¡¢Content¡¢Intelligent Hub¡¢Notebook¡¢People¡¢PIV-D¡¢WebÒÔ¼°ÊÊÓÃÓÚApache CordovaºÍXamarinµÄSDK²å¼þ ¡£¡£¡£¡£¡£Æ¾Ö¤Ç徲ͨ¸æ£¬£¬£¬£¬ÈôÊÇÆôÓÃÁËSSL Pinning£¬£¬£¬£¬ÔòÔÚÊÜÓ°ÏìµÄÒÆ¶¯APPºÍWorkspace ONE UEM×°±¸Ð§ÀÍÖ®¼äµÄÖÐÐÄÈË£¨MITM£©¹¥»÷Õß¿ÉÄܲ¶»ñ´«ÊäÖеÄÃô¸ÐÊý¾Ý ¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/96446/security/vmware-tools-and-workspace-one-sdk-flaws.html


4.Peekaboo MomentsÒâÍâй¶80ÍòÓû§µÄÓÊÏäÐÅÏ¢


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Çå¾²Ñо¿Ô±Dan Ehrlich·¢Ã÷Peekaboo Moments APPµÄElasticsearchÊý¾Ý¿â̻¶ÁËÊýǧ¸öÓ¤¶ùµÄÕÕÆ¬ºÍÊÓÆµÒÔ¼°ÖÁÉÙ80Íò¸öµç×ÓÓʼþµØµã ¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âÊôÓÚPeekaboo MomentsµÄ¿ª·¢ÉÌBithouse£¬£¬£¬£¬Êý¾Ý¿âÖдæÓÐ7000Íò¸öÈÕÖ¾Îļþ ¡£¡£¡£¡£¡£³ýÁËÓ¤¶ùµÄÊÓÆµºÍÕÕÆ¬Í⣬£¬£¬£¬¸ÃÊý¾Ý¿â»¹°üÀ¨Ó¤¶ùµÄ³öÉúÈÕÆÚ¡¢Éí³¤ºÍÌåÖØÒÔ¼°¾­¶ÈºÍγ¶ÈλÖÃÊý¾Ý ¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬Ð¹Â¶µÄÊý¾ÝÒÉΪPeekaboo MomentsµÄFacebook APIÃÜÔ¿£¬£¬£¬£¬âïÊÑ¿ÉʹÓøÃÃÜÔ¿½«ÕÕÆ¬µÈÐû²¼µ½Facebook ¡£¡£¡£¡£¡£Æ¾Ö¤EhrlichµÄ˵·¨£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜ»áʹÓÃÕâЩÃÜÔ¿À´»á¼ûÓû§FacebookÒ³ÃæÉϵÄÄÚÈÝ ¡£¡£¡£¡£¡£BithouseÔÚ½Óµ½±¨¸æºóѸËÙ¶ÔЧÀÍÆ÷¾ÙÐÐÁ˱£»£»£»£»¤ ¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://hotforsecurity.bitdefender.com/blog/peekaboo-moments-app-left-baby-videos-photos-and-800000-users-email-addresses-exposed-on-the-internet-22067.html


5.¼ÓÄôóÍøÉÏÒ©µêPlanetDrugsDirectй¶²¿·Ö¿Í»§Ö§¸¶ÐÅÏ¢


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


¼ÓÄôóÍøÉÏÒ©µêPlanetDrugsDirectÕýÔÚͨ¹ýµç×ÓÓʼþ֪ͨ¿Í»§ÆäСÎÒ˽¼ÒºÍ²ÆÎñÐÅÏ¢Êܵ½Êý¾Ýй¶ÊÂÎñµÄÓ°Ïì ¡£¡£¡£¡£¡£PlanetDrugsDirect³Æ×Ô¼ºÎª¿Í»§Ìṩ»ñµÃ´¦·½Ò©ºÍ·Ç´¦·½Ò©µÄʱ»ú£¬£¬£¬£¬Æä¿Í»§ÊýĿԼΪ40Íò ¡£¡£¡£¡£¡£Æ¾Ö¤¸ÃÒ©µêµÄ֪ͨ£¬£¬£¬£¬¿ÉÄÜй¶µÄÊý¾Ý°üÀ¨¿Í»§µÄÐÕÃû¡¢×¡Ö·¡¢µç×ÓÓʼþµØµã¡¢µç»°ºÅÂëÒÔ¼°´¦·½µÄÒ½ÁÆÐÅÏ¢ºÍ¸¶¿îÐÅÏ¢£¬£¬£¬£¬µ«Ã»ÓÐÖ¤¾ÝÅú×¢Óû§µÄÃÜÂëÊܵ½Ë𺦠¡£¡£¡£¡£¡£PlanetDrugsDirect»¹Ö¸³ö¸ÃÊÂÎñÏÖÔÚÕýÔÚÊÓ²ìÖУ¬£¬£¬£¬½«¾¡¿ìÌṩ¸ü¶àÏêϸÐÅÏ¢ ¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/online-pharmacy-planetdrugsdirect-discloses-security-breach/


6.Êý°Ù¸öҽѧ³ÉÏñϵͳÔÚÍøÉÏ̻¶ÁËÊý°ÙÍò»¼ÕßµÄÊý¾Ý


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


µÂ¹úÇå¾²³§ÉÌGreenbone³ÆÊý°Ù¸ö¿É¹ûÕæ»á¼ûµÄҽѧ³ÉÏñϵͳÔÚ»¥ÁªÍøÉÏ̻¶ÁËÈ«ÇòÊý°ÙÍò»¼ÕßµÄÊý¾Ý ¡£¡£¡£¡£¡£¸ÃÏîÑо¿ÖصãÆÊÎöÔÚÍøÉÏ̻¶µÄҽѧͼƬ´æµµºÍͨѶϵͳ£¨PACS£©£¬£¬£¬£¬ÔÚËùÓÐÊÜÆÊÎöµÄPACSЧÀÍÆ÷ÖУ¬£¬£¬£¬ÓпìÒª1/4µÄϵͳ½«Êý¾Ý̻¶ÔÚ»¥ÁªÍøÉÏ ¡£¡£¡£¡£¡£ÏêϸÀ´Ëµ£¬£¬£¬£¬ÔÚ2019Äê7ÔÂÖÁ2019Äê9ÔÂÖ®¼äÆÊÎöµÄ2300¸öϵͳÖУ¬£¬£¬£¬ÓÐ590¸ö¿É´ÓInternet»á¼û²¢ÇÒδÉèÃÜÂ룬£¬£¬£¬¹²ÓÐÁè¼Ý2450ÍòÌõ»¼ÕßÊý¾Ý̻¶£¬£¬£¬£¬ÔÚ11Ô·ݵÄÑо¿ÖУ¬£¬£¬£¬¸Ã¹«Ë¾Í¸Â¶ÓÐ3500ÍòÌõ»¼Õ߼ͼ¿É¹ûÕæ»á¼û ¡£¡£¡£¡£¡£ÔÚ9ÔÂÖÁ11ÔÂÖ®¼ä£¬£¬£¬£¬°üÀ¨Ò½ÁÆÍ¼ÏñµÄ̻¶»¼Õ߼ͼÊýÄ¿ÒÑ´Ó440ÍòÔöÌíÁËÒ»±¶£¬£¬£¬£¬µÖ´ï900Íò ¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/unprotected-medical-systems-expose-data-millions-patients