Chrome¡¢EdgeºÍSafari¾ùÔÚÌ츮±Öб»¹¥ÆÆ£»Â·Ò×˹°²ÄÇÖݵ±¾ÖÔâÀÕË÷Èí¼þ¹¥»÷
°ä²¼¹¦·ò 2019-11-19
΢ÈíÔÚ11ÔÂOffice°²È«¸üÐÂÖÐΪ7¸ö·ÖÆçµÄ²úÆ·°ä²¼ÁË17¸ö°²È«¸üкÍ5¸öÀۼƸüУ¬ÆäÖÐ15¸öÓëδÊÚȨµÄÐÅÏ¢½Ó¼ûÓйء£Î¢ÈíÔÚ17¸öOffice°²È«¸üÐÂÖн¨¸´ÁË6¸öÐÅϢй¶·ì϶£¬Ô̺¬CVE-2019-1442¡¢CVE-2019-1443¡¢CVE-2019-1446¡¢CVE-2019-1448¡¢CVE-2019-1402ºÍCVE-2019-1409£¬ÊÜÓ°ÏìµÄ²úÆ·Ô̺¬Office 2010µ½Office 2016¡¢Excel 2010µ½Excel 2016¡¢SharePoint Server 2010µ½SharePoint Server 2019¡£Áí±íÁ½¸ö·ì϶»¹Ô̺¬SharePoint Server 2019˵»°°üºÍOffice Online·þÎñÆ÷ÖеݲȫÈƹý·ì϶£¨CVE-2019-1449ºÍCVE-2019-1457£©¡£ÆëÈ«·ì϶ÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-the-november-2019-security-updates-for-office/2¡¢¹È¸è½¨¸´Gmail¶¯Ì¬µç×ÓÓʼþÖ°ÄÜÖеÄXSS·ì϶
¹È¸è½¨¸´Gmail¶¯Ì¬µç×ÓÓʼþÖ°ÄÜÖеÄXSS·ì϶£¬Æ¾¾Ý×êÑÐÈËÔ±µÄ±íÊö£¬¸Ã·ì϶ÊÇDOM Clobbering¹¥»÷µÄÒ»¸öµäÐÍÀý×Ó¡£¸Ã·ì϶´æÔÚÓÚAMP4Email£¨Ò²³ÆÎª¶¯Ì¬µç×ÓÓʼþ£©Ö°ÄÜÖУ¬AMP4EmailÓµÓÐÒ»¸ö¹ýÂËXSSµÄÑé֤ϵͳ£¬µ«×êÑÐÈËÔ±·¢ÏÖ±êÇ©ÖÐidµÄÊôÐÔÊDZ»ÔÊÐíµÄ¡£ÔÚAMP4EmailÖУ¬idÊôÐÔµÄijЩֵÊܵ½ÏÞ¶È£¬µ«ÊÇ£¬ÔÚAMP_MODEÖÐÈôÊǸú¯Êý³¢ÊÔ¼ÓÔØJSÎļþ£¬ÔòÃýÎó»áµ¼ÖÂ404£¬´Ó¶øÔÚÁ˾ÖURLÖе¼Ö¡°Î´½ç˵¡±µÄ²¿ÃÅ¡£¹¥»÷Õß¿Éͨ¹ý½«payloadдÈëwindow.testLocationÀ´½ÚÔìURL¡£µ«ÔÚÏÖʵÇé¿öÖÐAMPµÄÄÚÈݰ²È«Õ½Êõ£¨CSP£©Ö°Äܽ«»á×èÖ¹´úÂëµÃµ½Ö´ÐС£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/google-patches-awesome-xss-vulnerability-in-gmail/3¡¢Ó¡¶ÈÃÀױƽ̨Nykaa API·ì϶¶³ö½ü100ÍòÓû§Êý¾Ý
Ó¡¶ÈÃÀ×±ÁãÊÛÆ½Ì¨Nykaa FashionÒѽ¨¸´Ò»¸ö¿Éµ¼Ö½ü100Íò¿Í»§ÐÅϢй¶µÄ·ì϶¡£ÕâÊÇÒ»¸öAPI·ì϶£¬¹¥»÷Õߣ¨ÀýÈçºÚ¿Í»òµç»°ÍÆÏúÔ±£©¿ÉÀûÓÃ×Ô¶¯»¯¾ç±¾»ñÈ¡Óû§Êý¾Ý£¬Ô̺¬¶©µ¥¾ßÌåÐÅÏ¢¡¢Óʼþ±êʶ¡¢ÐÕÃû¡¢µç»°ºÅÂëºÍµç×ÓÓʼþµØÖ·¡£NykaaÊ×ϯ¼¼Êõ¹ÙSanjay SuriÔÚÒ»·ÝÉêÃ÷ÖаµÊ¾£¬¸Ã¹«Ë¾ÒѾ½â¾öÁ˸ÃÎÊÌâ²¢ÇÒûÓÐÓ×ÎÒ»ò²ÆÕþÊý¾Ýй¶¡£
ÔÎÄÁ´½Ó£º
https://economictimes.indiatimes.com/small-biz/startups/newsbuzz/nykaa-fixes-a-data-security-bug/articleshow/72101784.cms4¡¢Chrome¡¢EdgeºÍSafari¾ùÔÚÌ츮±Öб»¹¥ÆÆ
ÔÚ11ÔÂ16ÈÕÖÁ17Èճɶ¼½øÐеÄÌ츮±ÉÏ£¬Edge¡¢Chrome¡¢Safari¾ù±»²ÎÈüÕß¹¥ÆÆ£¬ÆäËü±»¹¥ÆÆµÄ²úÆ·»¹Ô̺¬Office 365¡¢iOS¡¢Ó×Ãס¢Vivo¡¢VirtualBox¡¢ÓÑѶ¿Æ¼¼µÄ·ÓÉÆ÷¡¢Adobe PDF ºÍ VMWare WorkstationµÈ¡£Õâ´Î´óÈüÉϹ²ÓÐ23Ö§ÐÐÁвÎÈü£¬ÈüÔìÀàËÆÓÚPwn2Own£¬¹²ÉèÖÃÁË100ÍòÃÀÔª½±½ð³Ø¡£ÔÚÕâ´ÎΪÆÚÁ½ÌìµÄ½ÇÖðÖУ¬¹²ÓÐ20´Î¹¥»÷³¢ÊԵõ½³É¹¦£¬²ÎÈüÕßÒ»¹²Ó®µÃÁË54.5ÍòÃÀÔªµÄ½±½ð¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/chrome-edge-safari-hacked-at-elite-chinese-hacking-contest/
5¡¢Ð´¹µö»î¶¯ÖØÒªÕë¶ÔMicrosoft OfficeÖÎÀíÔ±
PhishLabs·¢ÏÖÒ»¸öÕë¶ÔMicrosoft Office 365ÖÎÀíÔ±µÄÍøÂç´¹µö»î¶¯¡£¸Ã»î¶¯Ê¼ÓÚ´¹µöÓʼþ£¬Óʼþ¼Ù×°³ÉÀ´×ÔMicrosoft£¬²¢ÔÚ¶¥²¿ÏÔʾOffice 365µÄlogo£¬µ«ËüÀ´×Ô²»ÊôÓÚMicrosoftµÄ¾¹ýÑéÖ¤µÄÓò¡£ÈôÊÇÊÕ¼þÈ˵ã»÷ÁËÓʼþÖеÄÁ´½Ó£¬Ôò»á±»³Á¶¨Ïòµ½ÐéαµÄOffice 365µÇÂ¼Ò³Ãæ¡£¹¥»÷ÕßרÃÅÕë¶ÔÖÎÀíÔ±µÄÍ´´¦£¬Í¨¹ýÈëÇÖÖÎÀíÔ¹ØË»§£¬ËûÃÇÄܹ»Ç±ÔڵؽÚÔìÓë¸ø¶¨Óò¹ØÁªµÄÆäËûµç×ÓÓʼþÕÊ»§£¬»¹Äܹ»ÀûÓÃÖÎÀíÔ¹ØÊ»§µÄȨÏÞÀ´´´½¨ÆäËûÕÊ»§£¬½øÐиü¶à¶ñÒâ¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://www.tripwire.com/state-of-security/security-data-protection/phishers-targeting-microsoft-office-365-admin-credentials/
6¡¢Â·Ò×˹°²ÄÇÖݵ±¾ÖÔâÀÕË÷Èí¼þ¹¥»÷µ¼ÖÂÍ£°Ú
11ÔÂ18ÈÕ·Ò×˹°²ÄÇÖݵ±¾ÖÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬Ô̺¬³µÁ¾ÖÎÀí°ì¹«ÊÒ¡¢ÎÀÉú²¿¡¢ÔËÊäÓë·¢Õ¹²¿ÔÚÄڵĶà¸öÖݲ¿ÃÅÒÑÍ£°Ú¡£¸Ã¹¥»÷ÊÇÔÚ11µã»ã±¨µÄ£¬´Ëǰ¸ÃÖÝÒÑÇ¿Ôì¹Ø¹ØÁËÓɸÃÖÝÔËÓªµÄ¶à¶àÍøÕ¾¼°µç×ÓÓʼþ·þÎñ¡£¾Ý±¾µØÃ½Ì屨·£¬¸ÃÖݵĶà¸ö·þÎñ»ú¹¹¶¼Êܵ½×ÌÈÅ£¬Ô̺¬79¸ö»ú¶¯³µ°ì¹«ÊÒ¡£Öݳ¤John Bel Edwards°µÊ¾ËûÒѼ¤Éú·Ò×˹°²ÄÇÖݵÄÍøÂ簲ȫÍŶÓÀ´Ðµ÷Õâ´Î¹¥»÷Ôì³ÉµÄ·ÛË顣ĿǰÉв»Ã÷ÏԸù¥»÷ÊÂÎñÖÐÀÕË÷Èí¼þµÄÀàÐÍ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/louisiana-government-suffers-outage-due-to-ransomware-attack/


¾©¹«Íø°²±¸11010802024551ºÅ