Chrome¡¢EdgeºÍSafari¾ùÔÚÌ츮±­Öб»¹¥ÆÆ£»£»£»£»£»£»£»£»Â·Ò×˹°²ÄÇÖݵ±¾ÖÔâÀÕË÷Èí¼þ¹¥»÷

°ä²¼¹¦·ò 2019-11-19
1¡¢Î¢Èí°ä²¼11ÔÂOffice°²È«¸üУ¬ £¬£¬£¬£¬ £¬£¬£¬½¨¸´¶à¸ö·ì϶

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

΢ÈíÔÚ11ÔÂOffice°²È«¸üÐÂÖÐΪ7¸ö·ÖÆçµÄ²úÆ·°ä²¼ÁË17¸ö°²È«¸üкÍ5¸öÀۼƸüУ¬ £¬£¬£¬£¬ £¬£¬£¬ÆäÖÐ15¸öÓëδÊÚȨµÄÐÅÏ¢½Ó¼ûÓйء£¡£ ¡£¡£¡£ ¡£Î¢ÈíÔÚ17¸öOffice°²È«¸üÐÂÖн¨¸´ÁË6¸öÐÅϢй¶·ì϶£¬ £¬£¬£¬£¬ £¬£¬£¬Ô̺¬CVE-2019-1442¡¢CVE-2019-1443¡¢CVE-2019-1446¡¢CVE-2019-1448¡¢CVE-2019-1402ºÍCVE-2019-1409£¬ £¬£¬£¬£¬ £¬£¬£¬ÊÜÓ°ÏìµÄ²úÆ·Ô̺¬Office 2010µ½Office 2016¡¢Excel 2010µ½Excel 2016¡¢SharePoint Server 2010µ½SharePoint Server 2019¡£¡£ ¡£¡£¡£ ¡£Áí±íÁ½¸ö·ì϶»¹Ô̺¬SharePoint Server 2019˵»°°üºÍOffice Online·þÎñÆ÷ÖеݲȫÈƹý·ì϶£¨CVE-2019-1449ºÍCVE-2019-1457£©¡£¡£ ¡£¡£¡£ ¡£ÆëÈ«·ì϶ÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£ ¡£¡£¡£ ¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-the-november-2019-security-updates-for-office/

2¡¢¹È¸è½¨¸´Gmail¶¯Ì¬µç×ÓÓʼþÖ°ÄÜÖеÄXSS·ì϶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¹È¸è½¨¸´Gmail¶¯Ì¬µç×ÓÓʼþÖ°ÄÜÖеÄXSS·ì϶£¬ £¬£¬£¬£¬ £¬£¬£¬Æ¾¾Ý×êÑÐÈËÔ±µÄ±íÊö£¬ £¬£¬£¬£¬ £¬£¬£¬¸Ã·ì϶ÊÇDOM Clobbering¹¥»÷µÄÒ»¸öµäÐÍÀý×Ó¡£¡£ ¡£¡£¡£ ¡£¸Ã·ì϶´æÔÚÓÚAMP4Email£¨Ò²³ÆÎª¶¯Ì¬µç×ÓÓʼþ£©Ö°ÄÜÖУ¬ £¬£¬£¬£¬ £¬£¬£¬AMP4EmailÓµÓÐÒ»¸ö¹ýÂËXSSµÄÑé֤ϵͳ£¬ £¬£¬£¬£¬ £¬£¬£¬µ«×êÑÐÈËÔ±·¢ÏÖ±êÇ©ÖÐidµÄÊôÐÔÊDZ»ÔÊÐíµÄ¡£¡£ ¡£¡£¡£ ¡£ÔÚAMP4EmailÖУ¬ £¬£¬£¬£¬ £¬£¬£¬idÊôÐÔµÄijЩֵÊܵ½ÏÞ¶È£¬ £¬£¬£¬£¬ £¬£¬£¬µ«ÊÇ£¬ £¬£¬£¬£¬ £¬£¬£¬ÔÚAMP_MODEÖÐÈôÊǸú¯Êý³¢ÊÔ¼ÓÔØJSÎļþ£¬ £¬£¬£¬£¬ £¬£¬£¬ÔòÃýÎó»áµ¼ÖÂ404£¬ £¬£¬£¬£¬ £¬£¬£¬´Ó¶øÔÚÁ˾ÖURLÖе¼Ö¡°Î´½ç˵¡±µÄ²¿ÃÅ¡£¡£ ¡£¡£¡£ ¡£¹¥»÷Õß¿Éͨ¹ý½«payloadдÈëwindow.testLocationÀ´½ÚÔìURL¡£¡£ ¡£¡£¡£ ¡£µ«ÔÚÏÖʵÇé¿öÖÐAMPµÄÄÚÈݰ²È«Õ½Êõ£¨CSP£©Ö°Äܽ«»á×èÖ¹´úÂëµÃµ½Ö´ÐÓ×£¡£ ¡£¡£¡£ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/google-patches-awesome-xss-vulnerability-in-gmail/

3¡¢Ó¡¶ÈÃÀױƽ̨Nykaa API·ì϶¶³ö½ü100ÍòÓû§Êý¾Ý

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

Ó¡¶ÈÃÀ×±ÁãÊÛÆ½Ì¨Nykaa FashionÒѽ¨¸´Ò»¸ö¿Éµ¼Ö½ü100Íò¿Í»§ÐÅϢй¶µÄ·ì϶¡£¡£ ¡£¡£¡£ ¡£ÕâÊÇÒ»¸öAPI·ì϶£¬ £¬£¬£¬£¬ £¬£¬£¬¹¥»÷Õߣ¨ÀýÈçºÚ¿Í»òµç»°ÍÆÏúÔ±£©¿ÉÀûÓÃ×Ô¶¯»¯¾ç±¾»ñÈ¡Óû§Êý¾Ý£¬ £¬£¬£¬£¬ £¬£¬£¬Ô̺¬¶©µ¥¾ßÌåÐÅÏ¢¡¢Óʼþ±êʶ¡¢ÐÕÃû¡¢µç»°ºÅÂëºÍµç×ÓÓʼþµØÖ·¡£¡£ ¡£¡£¡£ ¡£NykaaÊ×ϯ¼¼Êõ¹ÙSanjay SuriÔÚÒ»·ÝÉêÃ÷ÖаµÊ¾£¬ £¬£¬£¬£¬ £¬£¬£¬¸Ã¹«Ë¾ÒѾ­½â¾öÁ˸ÃÎÊÌâ²¢ÇÒûÓÐÓ×ÎÒ»ò²ÆÕþÊý¾Ýй¶¡£¡£ ¡£¡£¡£ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://economictimes.indiatimes.com/small-biz/startups/newsbuzz/nykaa-fixes-a-data-security-bug/articleshow/72101784.cms

4¡¢Chrome¡¢EdgeºÍSafari¾ùÔÚÌ츮±­Öб»¹¥ÆÆ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÔÚ11ÔÂ16ÈÕÖÁ17Èճɶ¼½øÐеÄÌ츮±­ÉÏ£¬ £¬£¬£¬£¬ £¬£¬£¬Edge¡¢Chrome¡¢Safari¾ù±»²ÎÈüÕß¹¥ÆÆ£¬ £¬£¬£¬£¬ £¬£¬£¬ÆäËü±»¹¥ÆÆµÄ²úÆ·»¹Ô̺¬Office 365¡¢iOS¡¢Ó×Ãס¢Vivo¡¢VirtualBox¡¢ÓÑѶ¿Æ¼¼µÄ·ÓÉÆ÷¡¢Adobe PDF ºÍ VMWare WorkstationµÈ¡£¡£ ¡£¡£¡£ ¡£Õâ´Î´óÈüÉϹ²ÓÐ23Ö§ÐÐÁвÎÈü£¬ £¬£¬£¬£¬ £¬£¬£¬ÈüÔìÀàËÆÓÚPwn2Own£¬ £¬£¬£¬£¬ £¬£¬£¬¹²ÉèÖÃÁË100ÍòÃÀÔª½±½ð³Ø¡£¡£ ¡£¡£¡£ ¡£ÔÚÕâ´ÎΪÆÚÁ½ÌìµÄ½ÇÖðÖУ¬ £¬£¬£¬£¬ £¬£¬£¬¹²ÓÐ20´Î¹¥»÷³¢ÊԵõ½³É¹¦£¬ £¬£¬£¬£¬ £¬£¬£¬²ÎÈüÕßÒ»¹²Ó®µÃÁË54.5ÍòÃÀÔªµÄ½±½ð¡£¡£ ¡£¡£¡£ ¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/chrome-edge-safari-hacked-at-elite-chinese-hacking-contest/

5¡¢Ð´¹µö»î¶¯ÖØÒªÕë¶ÔMicrosoft OfficeÖÎÀíÔ±


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


PhishLabs·¢ÏÖÒ»¸öÕë¶ÔMicrosoft Office 365ÖÎÀíÔ±µÄÍøÂç´¹µö»î¶¯¡£¡£ ¡£¡£¡£ ¡£¸Ã»î¶¯Ê¼ÓÚ´¹µöÓʼþ£¬ £¬£¬£¬£¬ £¬£¬£¬Óʼþ¼Ù×°³ÉÀ´×ÔMicrosoft£¬ £¬£¬£¬£¬ £¬£¬£¬²¢ÔÚ¶¥²¿ÏÔʾOffice 365µÄlogo£¬ £¬£¬£¬£¬ £¬£¬£¬µ«ËüÀ´×Ô²»ÊôÓÚMicrosoftµÄ¾­¹ýÑéÖ¤µÄÓò¡£¡£ ¡£¡£¡£ ¡£ÈôÊÇÊÕ¼þÈ˵ã»÷ÁËÓʼþÖеÄÁ´½Ó£¬ £¬£¬£¬£¬ £¬£¬£¬Ôò»á±»³Á¶¨Ïòµ½ÐéαµÄOffice 365µÇÂ¼Ò³Ãæ¡£¡£ ¡£¡£¡£ ¡£¹¥»÷ÕßרÃÅÕë¶ÔÖÎÀíÔ±µÄÍ´´¦£¬ £¬£¬£¬£¬ £¬£¬£¬Í¨¹ýÈëÇÖÖÎÀíÔ¹ØË»§£¬ £¬£¬£¬£¬ £¬£¬£¬ËûÃÇÄܹ»Ç±ÔڵؽÚÔìÓë¸ø¶¨Óò¹ØÁªµÄÆäËûµç×ÓÓʼþÕÊ»§£¬ £¬£¬£¬£¬ £¬£¬£¬»¹Äܹ»ÀûÓÃÖÎÀíÔ¹ØÊ»§µÄȨÏÞÀ´´´½¨ÆäËûÕÊ»§£¬ £¬£¬£¬£¬ £¬£¬£¬½øÐиü¶à¶ñÒâ¹¥»÷¡£¡£ ¡£¡£¡£ ¡£

Ô­ÎÄÁ´½Ó£º
https://www.tripwire.com/state-of-security/security-data-protection/phishers-targeting-microsoft-office-365-admin-credentials/

6¡¢Â·Ò×˹°²ÄÇÖݵ±¾ÖÔâÀÕË÷Èí¼þ¹¥»÷µ¼ÖÂÍ£°Ú


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


11ÔÂ18ÈÕ·Ò×˹°²ÄÇÖݵ±¾ÖÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬ £¬£¬£¬£¬ £¬£¬£¬Ô̺¬³µÁ¾ÖÎÀí°ì¹«ÊÒ¡¢ÎÀÉú²¿¡¢ÔËÊäÓë·¢Õ¹²¿ÔÚÄڵĶà¸öÖݲ¿ÃÅÒÑÍ£°Ú¡£¡£ ¡£¡£¡£ ¡£¸Ã¹¥»÷ÊÇÔÚ11µã»ã±¨µÄ£¬ £¬£¬£¬£¬ £¬£¬£¬´Ëǰ¸ÃÖÝÒÑÇ¿Ôì¹Ø¹ØÁËÓɸÃÖÝÔËÓªµÄ¶à¶àÍøÕ¾¼°µç×ÓÓʼþ·þÎñ¡£¡£ ¡£¡£¡£ ¡£¾Ý±¾µØÃ½Ì屨·£¬ £¬£¬£¬£¬ £¬£¬£¬¸ÃÖݵĶà¸ö·þÎñ»ú¹¹¶¼Êܵ½×ÌÈÅ£¬ £¬£¬£¬£¬ £¬£¬£¬Ô̺¬79¸ö»ú¶¯³µ°ì¹«ÊÒ¡£¡£ ¡£¡£¡£ ¡£Öݳ¤John Bel Edwards°µÊ¾ËûÒѼ¤Éú·Ò×˹°²ÄÇÖݵÄÍøÂ簲ȫÍŶÓÀ´Ð­µ÷Õâ´Î¹¥»÷Ôì³ÉµÄ·ÛËé¡£¡£ ¡£¡£¡£ ¡£Ä¿Ç°Éв»Ã÷ÏԸù¥»÷ÊÂÎñÖÐÀÕË÷Èí¼þµÄÀàÐÍ¡£¡£ ¡£¡£¡£ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/louisiana-government-suffers-outage-due-to-ransomware-attack/