CVE-2020-3495 | Cisco JabberÔ¶³Ì´úÂëÖ´Ðзì϶¹«¸æ
°ä²¼¹¦·ò 2020-09-030x00 ·ì϶¸ÅÊö
CVE ID | CVE-2020-3495 | ʱ ¼ä | 2020-09-03 |
Àà ÐÍ | RCE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | ËùÓкÏÓÃWindows Cisco Jabber¿Í»§¶Ë°æ±¾£¨12.1ÖÁ12.9£© |
2020Äê09ÔÂ02ÈÕ£¬Cisco¹Ù·½½¨¸´ÁËÒ»¸öÑϳÁµÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-3495£©£¬¸Ã·ì϶CVSSÆÀ·ÖΪ9.9·Ö¡£
CVE-2020-3495·ì϶ÓÉWatchcomµÄ°²È«×êÑÐÈËÔ±Olav Sortland Thoresen·¢ÏÖ²¢»ã±¨£¬Ë¼¿Æ²úÆ·°²È«ÊÂÎñÏìÓ¦ÍŶӣ¨PSIRT£©°µÊ¾¸Ã·ì϶µ±Ç°ÉÐδ±»¿í·ºÀûÓá£
0x01 ·ì϶ÏêÇé

Cisco Jabber for WindowsÊÇÒ»¿î×ÀÃæºÏ×÷ÀûÓ÷¨Ê½£¬ÖØÒªÎªÓû§Ìṩ״̬¡¢¼´Ê±ÐÂÎÅ£¨IM£©¡¢ÐÂÎÅ¡¢×ÀÃæ¹²Ïí¡¢ÊÓÆµÒôƵ»áÒéºÍWeb»áÒé·þÎñ¡£
CVE-2020-3495ÊÇÓÉÓÚÓʼþÄÚÈÝÑéÖ¤²»ÕýÈ·ÒýÆðµÄ¡£¹¥»÷Õßͨ¹ýʹÓöñÒâµÄ¿ÉÀ©´óÐÂÎźÍ״̬ºÍ̸£¨XMPP£©ÐÂÎÅÀ´ÀûÓô˷ì϶£¬Í¨¹ýÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÔÚδ´ò²¹¶¡µÄ Cisco Jabber for Windows µÄϵͳÉÏÖ´ÐжñÒâ´úÂë¡£²¢ÇÒ£¬¸Ã·ì϶µÄÀûÓò»±ØÒªÓû§½»»¥£¬µ±Jabber for Windows¿Í»§¶ËÔÚºó¶ÜÔËÐÐʱ¸Ã·ì϶Ҳ¿É±»ÀûÓá£
µ«ÈôÊÇÒªÀûÓô˷ì϶£¬¹¥»÷Õß±ØÐë¿ÉÄÜÏòÔËÐÐWindowsµÄCisco JabberµÄ×îÖÕÓû§ÏµÍ³·¢ËÍXMPPÐÂÎÅ¡£Èô³É¹¦ÀûÓô˷ì϶£¬»áµ¼ÖÂÀûÓ÷¨Ê½ÔËÐеı¾µØÎļþõè¾¶Öб»ÉÏ´«ËÁÒâÖ´ÐÐÎļþ£¬¸Ã¿ÉÖ´ÐÐÎļþ½«»áÒÔÆô¶¯Jabber¿Í»§¶ËÀûÓ÷¨Ê½µÄÓû§µÄÌØÈ¨ÔÚÓû§ÏµÍ³ÉÏÔËÐС£
µ«½öÔÚphone-only modeģʽÏÂʹÓÃJabber²¢ÇÒûÓÐÆôÓÃXMPPÐÂÎÅ·þÎñʱϵͳ²»Ò×Êܵ½¹¥»÷£¬µ±JabberÉèÖÃΪʹÓóýXMPPÐÂÎÅ´«µÝÒÔ±íµÄÐÂÎÅ´«µÝ·þÎñʱ£¬¸Ã·ì϶ÔòÎÞ·¨±»ÀûÓá£
0x02 ´ëÖý¨Òé
½¨ÒéÉý¼¶µ½Êʵ±µÄ°æ±¾£º
ÊÜÓ°Ïì°æ±¾ | ¸üа汾 |
12.1 | 12.1.3 |
12.5 | 12.5.2 |
12.6 | 12.6.3 |
12.7 | 12.7.2 |
12.8 | 12.8.3 |
12.9 | 12.9.1 |
ÏÂÔØµØÖ·£º
https://software.cisco.com/download/home/284324806/type/284006014/release/12.6(3)
0x03 ÓйØÐÂÎÅ
https://www.bleepingcomputer.com/news/security/cisco-fixes-critical-code-execution-bug-in-jabber-for-windows/
https://securityaffairs.co/wordpress/107834/security/cisco-jabber-for-windows-flaw.html
0x04 ²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-jabber-UyTKCPGg
0x05 ¹¦·òÏß
2020-09-02 Cisco°ä²¼°²È«²¼¸æ
2020-09-03 VSRC°ä²¼°²È«¹«¸æ



¾©¹«Íø°²±¸11010802024551ºÅ