Chrome¡¢EdgeºÍSafari¾ùÔÚÌ츮±­Öб»¹¥ÆÆ £»Â·Ò×˹°²ÄÇÖݵ±¾ÖÔâÀÕË÷Èí¼þ¹¥»÷

°ä²¼¹¦·ò 2019-11-19
1¡¢Î¢Èí°ä²¼11ÔÂOffice°²È«¸üУ¬½¨¸´¶à¸ö·ì϶

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

΢ÈíÔÚ11ÔÂOffice°²È«¸üÐÂÖÐΪ7¸ö·ÖÆçµÄ²úÆ·°ä²¼ÁË17¸ö°²È«¸üкÍ5¸öÀۼƸüУ¬ÆäÖÐ15¸öÓëδÊÚȨµÄÐÅÏ¢½Ó¼ûÓйØ ¡£Î¢ÈíÔÚ17¸öOffice°²È«¸üÐÂÖн¨¸´ÁË6¸öÐÅϢй¶·ì϶£¬Ô̺¬CVE-2019-1442¡¢CVE-2019-1443¡¢CVE-2019-1446¡¢CVE-2019-1448¡¢CVE-2019-1402ºÍCVE-2019-1409£¬ÊÜÓ°ÏìµÄ²úÆ·Ô̺¬Office 2010µ½Office 2016¡¢Excel 2010µ½Excel 2016¡¢SharePoint Server 2010µ½SharePoint Server 2019 ¡£Áí±íÁ½¸ö·ì϶»¹Ô̺¬SharePoint Server 2019˵»°°üºÍOffice Online·þÎñÆ÷ÖеݲȫÈƹý·ì϶£¨CVE-2019-1449ºÍCVE-2019-1457£© ¡£ÆëÈ«·ì϶ÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó ¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-the-november-2019-security-updates-for-office/

2¡¢¹È¸è½¨¸´Gmail¶¯Ì¬µç×ÓÓʼþÖ°ÄÜÖеÄXSS·ì϶


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¹È¸è½¨¸´Gmail¶¯Ì¬µç×ÓÓʼþÖ°ÄÜÖеÄXSS·ì϶£¬Æ¾¾Ý×êÑÐÈËÔ±µÄ±íÊö£¬¸Ã·ì϶ÊÇDOM Clobbering¹¥»÷µÄÒ»¸öµäÐÍÀý×Ó ¡£¸Ã·ì϶´æÔÚÓÚAMP4Email£¨Ò²³ÆÎª¶¯Ì¬µç×ÓÓʼþ£©Ö°ÄÜÖУ¬AMP4EmailÓµÓÐÒ»¸ö¹ýÂËXSSµÄÑé֤ϵͳ£¬µ«×êÑÐÈËÔ±·¢ÏÖ±êÇ©ÖÐidµÄÊôÐÔÊDZ»ÔÊÐíµÄ ¡£ÔÚAMP4EmailÖУ¬idÊôÐÔµÄijЩֵÊܵ½ÏÞ¶È£¬µ«ÊÇ£¬ÔÚAMP_MODEÖÐÈôÊǸú¯Êý³¢ÊÔ¼ÓÔØJSÎļþ£¬ÔòÃýÎó»áµ¼ÖÂ404£¬´Ó¶øÔÚÁ˾ÖURLÖе¼Ö¡°Î´½ç˵¡±µÄ²¿ÃÅ ¡£¹¥»÷Õß¿Éͨ¹ý½«payloadдÈëwindow.testLocationÀ´½ÚÔìURL ¡£µ«ÔÚÏÖʵÇé¿öÖÐAMPµÄÄÚÈݰ²È«Õ½Êõ£¨CSP£©Ö°Äܽ«»á×èÖ¹´úÂëµÃµ½Ö´ÐÐ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/google-patches-awesome-xss-vulnerability-in-gmail/

3¡¢Ó¡¶ÈÃÀױƽ̨Nykaa API·ì϶¶³ö½ü100ÍòÓû§Êý¾Ý

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

Ó¡¶ÈÃÀ×±ÁãÊÛÆ½Ì¨Nykaa FashionÒѽ¨¸´Ò»¸ö¿Éµ¼Ö½ü100Íò¿Í»§ÐÅϢй¶µÄ·ì϶ ¡£ÕâÊÇÒ»¸öAPI·ì϶£¬¹¥»÷Õߣ¨ÀýÈçºÚ¿Í»òµç»°ÍÆÏúÔ±£©¿ÉÀûÓÃ×Ô¶¯»¯¾ç±¾»ñÈ¡Óû§Êý¾Ý£¬Ô̺¬¶©µ¥¾ßÌåÐÅÏ¢¡¢Óʼþ±êʶ¡¢ÐÕÃû¡¢µç»°ºÅÂëºÍµç×ÓÓʼþµØÖ· ¡£NykaaÊ×ϯ¼¼Êõ¹ÙSanjay SuriÔÚÒ»·ÝÉêÃ÷ÖаµÊ¾£¬¸Ã¹«Ë¾ÒѾ­½â¾öÁ˸ÃÎÊÌâ²¢ÇÒûÓÐÓ×ÎÒ»ò²ÆÕþÊý¾Ýй¶ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://economictimes.indiatimes.com/small-biz/startups/newsbuzz/nykaa-fixes-a-data-security-bug/articleshow/72101784.cms

4¡¢Chrome¡¢EdgeºÍSafari¾ùÔÚÌ츮±­Öб»¹¥ÆÆ


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ÔÚ11ÔÂ16ÈÕÖÁ17Èճɶ¼½øÐеÄÌ츮±­ÉÏ£¬Edge¡¢Chrome¡¢Safari¾ù±»²ÎÈüÕß¹¥ÆÆ£¬ÆäËü±»¹¥ÆÆµÄ²úÆ·»¹Ô̺¬Office 365¡¢iOS¡¢Ó×Ãס¢Vivo¡¢VirtualBox¡¢ÓÑѶ¿Æ¼¼µÄ·ÓÉÆ÷¡¢Adobe PDF ºÍ VMWare WorkstationµÈ ¡£Õâ´Î´óÈüÉϹ²ÓÐ23Ö§ÐÐÁвÎÈü£¬ÈüÔìÀàËÆÓÚPwn2Own£¬¹²ÉèÖÃÁË100ÍòÃÀÔª½±½ð³Ø ¡£ÔÚÕâ´ÎΪÆÚÁ½ÌìµÄ½ÇÖðÖУ¬¹²ÓÐ20´Î¹¥»÷³¢ÊԵõ½³É¹¦£¬²ÎÈüÕßÒ»¹²Ó®µÃÁË54.5ÍòÃÀÔªµÄ½±½ð ¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/chrome-edge-safari-hacked-at-elite-chinese-hacking-contest/

5¡¢Ð´¹µö»î¶¯ÖØÒªÕë¶ÔMicrosoft OfficeÖÎÀíÔ±


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


PhishLabs·¢ÏÖÒ»¸öÕë¶ÔMicrosoft Office 365ÖÎÀíÔ±µÄÍøÂç´¹µö»î¶¯ ¡£¸Ã»î¶¯Ê¼ÓÚ´¹µöÓʼþ£¬Óʼþ¼Ù×°³ÉÀ´×ÔMicrosoft£¬²¢ÔÚ¶¥²¿ÏÔʾOffice 365µÄlogo£¬µ«ËüÀ´×Ô²»ÊôÓÚMicrosoftµÄ¾­¹ýÑéÖ¤µÄÓò ¡£ÈôÊÇÊÕ¼þÈ˵ã»÷ÁËÓʼþÖеÄÁ´½Ó£¬Ôò»á±»³Á¶¨Ïòµ½ÐéαµÄOffice 365µÇÂ¼Ò³Ãæ ¡£¹¥»÷ÕßרÃÅÕë¶ÔÖÎÀíÔ±µÄÍ´´¦£¬Í¨¹ýÈëÇÖÖÎÀíÔ¹ØË»§£¬ËûÃÇÄܹ»Ç±ÔڵؽÚÔìÓë¸ø¶¨Óò¹ØÁªµÄÆäËûµç×ÓÓʼþÕÊ»§£¬»¹Äܹ»ÀûÓÃÖÎÀíÔ¹ØÊ»§µÄȨÏÞÀ´´´½¨ÆäËûÕÊ»§£¬½øÐиü¶à¶ñÒâ¹¥»÷ ¡£

Ô­ÎÄÁ´½Ó£º
https://www.tripwire.com/state-of-security/security-data-protection/phishers-targeting-microsoft-office-365-admin-credentials/

6¡¢Â·Ò×˹°²ÄÇÖݵ±¾ÖÔâÀÕË÷Èí¼þ¹¥»÷µ¼ÖÂÍ£°Ú


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


11ÔÂ18ÈÕ·Ò×˹°²ÄÇÖݵ±¾ÖÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬Ô̺¬³µÁ¾ÖÎÀí°ì¹«ÊÒ¡¢ÎÀÉú²¿¡¢ÔËÊäÓë·¢Õ¹²¿ÔÚÄڵĶà¸öÖݲ¿ÃÅÒÑÍ£°Ú ¡£¸Ã¹¥»÷ÊÇÔÚ11µã»ã±¨µÄ£¬´Ëǰ¸ÃÖÝÒÑÇ¿Ôì¹Ø¹ØÁËÓɸÃÖÝÔËÓªµÄ¶à¶àÍøÕ¾¼°µç×ÓÓʼþ·þÎñ ¡£¾Ý±¾µØÃ½Ì屨·£¬¸ÃÖݵĶà¸ö·þÎñ»ú¹¹¶¼Êܵ½×ÌÈÅ£¬Ô̺¬79¸ö»ú¶¯³µ°ì¹«ÊÒ ¡£Öݳ¤John Bel Edwards°µÊ¾ËûÒѼ¤Éú·Ò×˹°²ÄÇÖݵÄÍøÂ簲ȫÍŶÓÀ´Ð­µ÷Õâ´Î¹¥»÷Ôì³ÉµÄ·ÛËé ¡£Ä¿Ç°Éв»Ã÷ÏԸù¥»÷ÊÂÎñÖÐÀÕË÷Èí¼þµÄÀàÐÍ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/louisiana-government-suffers-outage-due-to-ransomware-attack/