Chrome¡¢EdgeºÍSafari¾ùÔÚÌ츮±­Öб»¹¥ÆÆ£»Â·Ò×˹°²ÄÇÖݵ±¾ÖÔâÀÕË÷Èí¼þ¹¥»÷

°ä²¼¹¦·ò 2019-11-19
1¡¢Î¢Èí°ä²¼11ÔÂOffice°²È«¸üР£¬½¨¸´¶à¸ö·ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

΢ÈíÔÚ11ÔÂOffice°²È«¸üÐÂÖÐΪ7¸ö·ÖÆçµÄ²úÆ·°ä²¼ÁË17¸ö°²È«¸üкÍ5¸öÀۼƸüР£¬ÆäÖÐ15¸öÓëδÊÚȨµÄÐÅÏ¢½Ó¼ûÓйØ¡£Î¢ÈíÔÚ17¸öOffice°²È«¸üÐÂÖн¨¸´ÁË6¸öÐÅϢй¶·ì϶ £¬Ô̺¬CVE-2019-1442¡¢CVE-2019-1443¡¢CVE-2019-1446¡¢CVE-2019-1448¡¢CVE-2019-1402ºÍCVE-2019-1409 £¬ÊÜÓ°ÏìµÄ²úÆ·Ô̺¬Office 2010µ½Office 2016¡¢Excel 2010µ½Excel 2016¡¢SharePoint Server 2010µ½SharePoint Server 2019¡£Áí±íÁ½¸ö·ì϶»¹Ô̺¬SharePoint Server 2019˵»°°üºÍOffice Online·þÎñÆ÷ÖеݲȫÈƹý·ì϶£¨CVE-2019-1449ºÍCVE-2019-1457£©¡£ÆëÈ«·ì϶ÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-the-november-2019-security-updates-for-office/

2¡¢¹È¸è½¨¸´Gmail¶¯Ì¬µç×ÓÓʼþÖ°ÄÜÖеÄXSS·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¹È¸è½¨¸´Gmail¶¯Ì¬µç×ÓÓʼþÖ°ÄÜÖеÄXSS·ì϶ £¬Æ¾¾Ý×êÑÐÈËÔ±µÄ±íÊö £¬¸Ã·ì϶ÊÇDOM Clobbering¹¥»÷µÄÒ»¸öµäÐÍÀý×Ó¡£¸Ã·ì϶´æÔÚÓÚAMP4Email£¨Ò²³ÆÎª¶¯Ì¬µç×ÓÓʼþ£©Ö°ÄÜÖÐ £¬AMP4EmailÓµÓÐÒ»¸ö¹ýÂËXSSµÄÑé֤ϵͳ £¬µ«×êÑÐÈËÔ±·¢ÏÖ±êÇ©ÖÐidµÄÊôÐÔÊDZ»ÔÊÐíµÄ¡£ÔÚAMP4EmailÖÐ £¬idÊôÐÔµÄijЩֵÊܵ½ÏÞ¶È £¬µ«ÊÇ £¬ÔÚAMP_MODEÖÐÈôÊǸú¯Êý³¢ÊÔ¼ÓÔØJSÎļþ £¬ÔòÃýÎó»áµ¼ÖÂ404 £¬´Ó¶øÔÚÁ˾ÖURLÖе¼Ö¡°Î´½ç˵¡±µÄ²¿ÃÅ¡£¹¥»÷Õß¿Éͨ¹ý½«payloadдÈëwindow.testLocationÀ´½ÚÔìURL¡£µ«ÔÚÏÖʵÇé¿öÖÐAMPµÄÄÚÈݰ²È«Õ½Êõ£¨CSP£©Ö°Äܽ«»á×èÖ¹´úÂëµÃµ½Ö´ÐС£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/google-patches-awesome-xss-vulnerability-in-gmail/

3¡¢Ó¡¶ÈÃÀױƽ̨Nykaa API·ì϶¶³ö½ü100ÍòÓû§Êý¾Ý

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

Ó¡¶ÈÃÀ×±ÁãÊÛÆ½Ì¨Nykaa FashionÒѽ¨¸´Ò»¸ö¿Éµ¼Ö½ü100Íò¿Í»§ÐÅϢй¶µÄ·ì϶¡£ÕâÊÇÒ»¸öAPI·ì϶ £¬¹¥»÷Õߣ¨ÀýÈçºÚ¿Í»òµç»°ÍÆÏúÔ±£©¿ÉÀûÓÃ×Ô¶¯»¯¾ç±¾»ñÈ¡Óû§Êý¾Ý £¬Ô̺¬¶©µ¥¾ßÌåÐÅÏ¢¡¢Óʼþ±êʶ¡¢ÐÕÃû¡¢µç»°ºÅÂëºÍµç×ÓÓʼþµØÖ·¡£NykaaÊ×ϯ¼¼Êõ¹ÙSanjay SuriÔÚÒ»·ÝÉêÃ÷ÖаµÊ¾ £¬¸Ã¹«Ë¾ÒѾ­½â¾öÁ˸ÃÎÊÌâ²¢ÇÒûÓÐÓ×ÎÒ»ò²ÆÕþÊý¾Ýй¶¡£

  

Ô­ÎÄÁ´½Ó£º

https://economictimes.indiatimes.com/small-biz/startups/newsbuzz/nykaa-fixes-a-data-security-bug/articleshow/72101784.cms

4¡¢Chrome¡¢EdgeºÍSafari¾ùÔÚÌ츮±­Öб»¹¥ÆÆ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔÚ11ÔÂ16ÈÕÖÁ17Èճɶ¼½øÐеÄÌ츮±­ÉÏ £¬Edge¡¢Chrome¡¢Safari¾ù±»²ÎÈüÕß¹¥ÆÆ £¬ÆäËü±»¹¥ÆÆµÄ²úÆ·»¹Ô̺¬Office 365¡¢iOS¡¢Ó×Ãס¢Vivo¡¢VirtualBox¡¢ÓÑѶ¿Æ¼¼µÄ·ÓÉÆ÷¡¢Adobe PDF ºÍ VMWare WorkstationµÈ¡£Õâ´Î´óÈüÉϹ²ÓÐ23Ö§ÐÐÁвÎÈü £¬ÈüÔìÀàËÆÓÚPwn2Own £¬¹²ÉèÖÃÁË100ÍòÃÀÔª½±½ð³Ø¡£ÔÚÕâ´ÎΪÆÚÁ½ÌìµÄ½ÇÖðÖÐ £¬¹²ÓÐ20´Î¹¥»÷³¢ÊԵõ½³É¹¦ £¬²ÎÈüÕßÒ»¹²Ó®µÃÁË54.5ÍòÃÀÔªµÄ½±½ð¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/chrome-edge-safari-hacked-at-elite-chinese-hacking-contest/

5¡¢Ð´¹µö»î¶¯ÖØÒªÕë¶ÔMicrosoft OfficeÖÎÀíÔ±


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


PhishLabs·¢ÏÖÒ»¸öÕë¶ÔMicrosoft Office 365ÖÎÀíÔ±µÄÍøÂç´¹µö»î¶¯¡£¸Ã»î¶¯Ê¼ÓÚ´¹µöÓʼþ £¬Óʼþ¼Ù×°³ÉÀ´×ÔMicrosoft £¬²¢ÔÚ¶¥²¿ÏÔʾOffice 365µÄlogo £¬µ«ËüÀ´×Ô²»ÊôÓÚMicrosoftµÄ¾­¹ýÑéÖ¤µÄÓò¡£ÈôÊÇÊÕ¼þÈ˵ã»÷ÁËÓʼþÖеÄÁ´½Ó £¬Ôò»á±»³Á¶¨Ïòµ½ÐéαµÄOffice 365µÇÂ¼Ò³Ãæ¡£¹¥»÷ÕßרÃÅÕë¶ÔÖÎÀíÔ±µÄÍ´´¦ £¬Í¨¹ýÈëÇÖÖÎÀíÔ¹ØË»§ £¬ËûÃÇÄܹ»Ç±ÔڵؽÚÔìÓë¸ø¶¨Óò¹ØÁªµÄÆäËûµç×ÓÓʼþÕÊ»§ £¬»¹Äܹ»ÀûÓÃÖÎÀíÔ¹ØÊ»§µÄȨÏÞÀ´´´½¨ÆäËûÕÊ»§ £¬½øÐиü¶à¶ñÒâ¹¥»÷¡£

Ô­ÎÄÁ´½Ó£º
https://www.tripwire.com/state-of-security/security-data-protection/phishers-targeting-microsoft-office-365-admin-credentials/

6¡¢Â·Ò×˹°²ÄÇÖݵ±¾ÖÔâÀÕË÷Èí¼þ¹¥»÷µ¼ÖÂÍ£°Ú


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


11ÔÂ18ÈÕ·Ò×˹°²ÄÇÖݵ±¾ÖÔâµ½ÀÕË÷Èí¼þ¹¥»÷ £¬Ô̺¬³µÁ¾ÖÎÀí°ì¹«ÊÒ¡¢ÎÀÉú²¿¡¢ÔËÊäÓë·¢Õ¹²¿ÔÚÄڵĶà¸öÖݲ¿ÃÅÒÑÍ£°Ú¡£¸Ã¹¥»÷ÊÇÔÚ11µã»ã±¨µÄ £¬´Ëǰ¸ÃÖÝÒÑÇ¿Ôì¹Ø¹ØÁËÓɸÃÖÝÔËÓªµÄ¶à¶àÍøÕ¾¼°µç×ÓÓʼþ·þÎñ¡£¾Ý±¾µØÃ½Ì屨· £¬¸ÃÖݵĶà¸ö·þÎñ»ú¹¹¶¼Êܵ½×ÌÈÅ £¬Ô̺¬79¸ö»ú¶¯³µ°ì¹«ÊÒ¡£Öݳ¤John Bel Edwards°µÊ¾ËûÒѼ¤Éú·Ò×˹°²ÄÇÖݵÄÍøÂ簲ȫÍŶÓÀ´Ð­µ÷Õâ´Î¹¥»÷Ôì³ÉµÄ·ÛË顣ĿǰÉв»Ã÷ÏԸù¥»÷ÊÂÎñÖÐÀÕË÷Èí¼þµÄÀàÐÍ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/louisiana-government-suffers-outage-due-to-ransomware-attack/