2023年3月11日星期六

Google Chrome 多個漏洞

發佈日期: 2023年03月08日

風險: 中度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Google Chrome 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況,遠端執行程式碼,資料洩露,仿冒及繞過保安限制。


影響

  • 遠端執行程式碼
  • 阻斷服務
  • 資料洩露
  • 仿冒
  • 繞過保安限制

受影響之系統或技術

  • Google Chrome 111.0.5563.64 (Linux) 之前的版本
  • Google Chrome 111.0.5563.64 (Mac) 之前的版本
  • Google Chrome 111.0.5563.64/.65 (Windows) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 111.0.5563.64 (Linux) 或之後版本
  • 更新至 111.0.5563.64 (Mac) 或之後版本
  • 更新至 111.0.5563.64/.65 (Windows) 或之後版本

漏洞識別碼


資料來源


相關連結

Google Chrome Multiple Vulnerabilities

Release Date: 8 Mar 2023

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities were identified in Google Chrome. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition and remote code execution, information disclosure, spoofing, security restriction bypass on the targeted system.


Impact

  • Remote Code Execution
  • Denial of Service
  • Information Disclosure
  • Spoofing
  • Security Restriction Bypass

System / Technologies affected

  • Google Chrome prior to 111.0.5563.64 (Linux)
  • Google Chrome prior to 111.0.5563.64 (Mac)
  • Google Chrome prior to 111.0.5563.64/.65 (Windows)

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 111.0.5563.64 (Linux) or later
  • Update to version 111.0.5563.64 (Mac) or later
  • Update to version 111.0.5563.64/.65 (Windows) or later

Vulnerability Identifier


Source


Related Link

微軟每月保安更新 (2023年2月)

最後更新 2023年03月07日 發佈日期: 2023年02月15日

風險: 極高度風險

類型: 操作系統 - 視窗操作系統

類型: 視窗操作系統

[更新於 2023-03-07] 

CVE-2023-21716 的概念驗證碼已被公開,影響 Microsoft Word。此漏洞可以通過預覽惡意 RTF 文件檔並在記憶體資料被破壞後執行任意程式碼。

 

微軟已為產品提供本月保安更新:

 

受影響產品風險程度影響備註
SQL Server中度風險 中度風險遠端執行程式碼
仿冒
 
視窗極高度風險 極高度風險遠端執行程式碼
權限提升
阻斷服務
資料洩露

正被廣泛利用

CVE-2023-21823

CVE-2023-23376

延伸安全性更新 (ESU)極高度風險 極高度風險遠端執行程式碼
權限提升
阻斷服務
資料洩露

正被廣泛利用

CVE-2023-21823

CVE-2023-23376

Azure中度風險 中度風險權限提升
資料洩露
遠端執行程式碼
仿冒
 
微軟 Dynamics中度風險 中度風險遠端執行程式碼
仿冒
 
瀏覽器中度風險 中度風險仿冒
篡改
遠端執行程式碼
 
Exchange Server中度風險 中度風險遠端執行程式碼 
微軟 Office極高度風險 極高度風險仿冒
遠端執行程式碼
權限提升
資料洩露
繞過保安限制

正被廣泛利用

CVE-2023-21823

CVE-2023-21715

 

CVE-2023-21716

的概念驗證碼已被公開

開發者工具中度風險 中度風險權限提升
阻斷服務
遠端執行程式碼
 
Apps中度風險 中度風險遠端執行程式碼 
System Center中度風險 中度風險權限提升
繞過保安限制
 
Device中度風險 中度風險資料洩露 

 

「極高度風險」產品數目:3

「高度風險」產品數目:0

「中度風險」產品數目:9

「低度風險」產品數目:0

整體「風險程度」評估:極高度風險


影響

  • 阻斷服務
  • 遠端執行程式碼
  • 仿冒
  • 權限提升
  • 資料洩露
  • 篡改
  • 繞過保安限制

受影響之系統或技術

  • SQL Server
  • 視窗
  • 延伸安全性更新 (ESU)
  • Azure
  • 微軟 Dynamics
  • 瀏覽器
  • Exchange Server
  • 微軟 Office
  • 開發者工具
  • Apps
  • System Center
  • Device

解決方案

在安裝軟體之前,請先瀏覽軟體供應商之網站,以獲得更多詳細資料。

  • 安裝軟件供應商提供的修補程式。

漏洞識別碼


資料來源


相關連結

Microsoft Monthly Security Update (February 2023)

Last Update Date: 7 Mar 2023 Release Date: 15 Feb 2023

RISK: Extremely High Risk

TYPE: Operating Systems - Windows OS

TYPE: Windows OS

[Updated on 2023-03-07] 

Proof of Concept exploit code is publicly available for CVE-2023-21716, affecting Microsoft Word. The vulnerability could be exploited by previewing a malicious RTF document and execute arbitrary code after memory corruption.

 

Microsoft has released monthly security update for their products:

 

Vulnerable ProductRisk LevelImpactsNotes
SQL ServerMedium Risk Medium RiskRemote Code Execution
Spoofing
 
WindowsExtremely High Risk Extremely High RiskRemote Code Execution
Elevation of Privilege
Denial of Service
Information Disclosure

Exploit in the wild

CVE-2023-21823

CVE-2023-23376

Extended Security Updates (ESU)Extremely High Risk Extremely High RiskRemote Code Execution
Elevation of Privilege
Denial of Service
Information Disclosure

Exploit in the wild

CVE-2023-21823

CVE-2023-23376

AzureMedium Risk Medium RiskElevation of Privilege
Information Disclosure
Remote Code Execution
Spoofing
 
Microsoft DynamicsMedium Risk Medium RiskRemote Code Execution
Spoofing
 
BrowserMedium Risk Medium RiskSpoofing
Data Manipulation
Remote Code Execution
 
Exchange ServerMedium Risk Medium RiskRemote Code Execution 
Microsoft OfficeExtremely High Risk Extremely High RiskSpoofing
Remote Code Execution
Elevation of Privilege
Information Disclosure
Security Restriction Bypass

Exploit in the wild

CVE-2023-21823

CVE-2023-21715

 

Proof of Concept exploit code Is publicly available for CVE-2023-21716

Developer ToolsMedium Risk Medium RiskElevation of Privilege
Denial of Service
Remote Code Execution
 
AppsMedium Risk Medium RiskRemote Code Execution 
System CenterMedium Risk Medium RiskElevation of Privilege
Security Restriction Bypass
 
DeviceMedium Risk Medium RiskInformation Disclosure 

 

Number of 'Extremely High Risk' product(s): 3

Number of 'High Risk' product(s): 0

Number of 'Medium Risk' product(s): 9

Number of 'Low Risk' product(s): 0

Evaluation of overall 'Risk Level': Extremely High Risk


Impact

  • Denial of Service
  • Remote Code Execution
  • Spoofing
  • Elevation of Privilege
  • Information Disclosure
  • Data Manipulation
  • Security Restriction Bypass

System / Technologies affected

  • SQL Server
  • Windows
  • Extended Security Updates (ESU)
  • Azure
  • Microsoft Dynamics
  • Browser
  • Exchange Server
  • Microsoft Office
  • Developer Tools
  • Apps
  • System Center
  • Device

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  •  Apply fixes issued by the vendor.

Vulnerability Identifier


Source


Related Link

2023年3月6日星期一

ChromeOS 多個漏洞

發佈日期: 2023年03月06日

風險: 中度風險

類型: 操作系統 - 其他操作系統

類型: 其他操作系統

於 ChromeOS 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼。


影響

  • 遠端執行程式碼

受影響之系統或技術

  • LTC-108, 108.0.5359.221 之前的版本(平台版本:15183.8240)
  • LTS-102, 102.0.5005.197 之前的版本(平台版本:14695.187.0)

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式,詳情請參閱以下連結:

 


漏洞識別碼


資料來源


相關連結

ChromeOS Multiple Vulnerabilities

Release Date: 6 Mar 2023

RISK: Medium Risk

TYPE: Operating Systems - Others OS

TYPE: Others OS

Multiple vulnerabilities were identified in ChromeOS. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution on the targeted system.


Impact

  • Remote Code Execution

System / Technologies affected

  • Version prior to LTC-108, 108.0.5359.221 (Platform Version: 15183.8240)
  • Version prior to LTS-102, 102.0.5005.197 (Platform Version: 14695.187.0)

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor. For detail, please refer to the link below:

 


Vulnerability Identifier


Source


Related Link

Trusted Platform Module (TPM) 多個漏洞

發佈日期: 2023年03月06日

風險: 中度風險

類型: 用戶端 - 辦公室應用

類型: 辦公室應用

於 Trusted Platform Module (TPM) 發現多個漏洞。攻擊者可利用這些漏洞,於目標系統觸發敏感資料洩露及權限提升。

 

Trusted Platform Module (TPM) 技術是一種基於硬件的解決方案,可為主機上的操作系統提供安全的加密功能,使其能夠抵抗篡改。 TPM 可以硬件形式、虛擬 TPM 的管理程序形式或純基於軟件的方法來實踐。硬件和軟件製造商使用這些規範來開發符合標準的韌體,並為敏感的加密數據提供安全接口。 TPM 用於各種設備,從企業級硬件到物聯網 (IoT) 設備。


影響

  • 資料洩露
  • 權限提升

受影響之系統或技術

  • Trusted Platform Module (TPM) 2.0 參考庫規範 Level 00 (修訂版 01.59 2019 年 11 月)

解決方案

可以通過操作系統供應商或原始設備製造商 (OEM) 來完成與TPM有關之硬件及軟件更新。用戶可參考以下連結

 


漏洞識別碼


資料來源


相關連結

Trusted Platform Module (TPM) Multiple Vulnerabilities

Release Date: 6 Mar 2023

RISK: Medium Risk

TYPE: Clients - Productivity Products

TYPE: Productivity Products

Multiple vulnerabilities were identified in Trusted Platform Module (TPM). An attacker could exploit some of these vulnerabilities to trigger sensitive information disclosure and elevation of privilege on the targeted system.

 

Trusted Platform Module (TPM) technology is a hardware-based solution that provides secure cryptographic functions to the operating systems on modern computers, making it resistant to tampering. TPM can be implemented in hardware form, virtual TPM's in Hypervisor form or in a purely software-based implementation. Hardware and software manufacturers use these specifications to build firmware that complies with standards and provides a secure interface to sensitive cryptographic data. TPM is employed in a variety of devices, from enterprise-grade hardware to Internet of Things (IoT) appliances.


Impact

  • Information Disclosure
  • Elevation of Privilege

System / Technologies affected

  • Trusted Platform Module (TPM) 2.0 reference library specification Level 00, Revision 01.59 November 2019

Solutions

Apply any updates provided by hardware and software manufacturers. Updating the firmware of TPM chips may be necessary, and this can be done through an OS vendor or the original equipment manufacturer (OEM). Users can refer to the following link

 


Vulnerability Identifier


Source


Related Link

Ubuntu Linux 核心多個漏洞

發佈日期: 2023年03月06日

風險: 中度風險

類型: 操作系統 - LINUX

類型: LINUX

於 Ubuntu Products 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行任意程式碼及洩露敏感資料。


影響

  • 阻斷服務
  • 遠端執行程式碼
  • 資料洩露

受影響之系統或技術

  • Ubuntu 14.04
  • Ubuntu 20.04
  • Ubuntu 22.04
  • Ubuntu 22.10

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Ubuntu Linux Kernel Multiple Vulnerabilities

Release Date: 6 Mar 2023

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities were identified in Ubuntu Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution and sensitive information disclosure on the targeted system.


Impact

  • Denial of Service
  • Remote Code Execution
  • Information Disclosure

System / Technologies affected

  • Ubuntu 14.04
  • Ubuntu 20.04
  • Ubuntu 22.04
  • Ubuntu 22.10

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

2023年3月3日星期五

SUSE Linux 內核多個漏洞

最後更新 2023年03月03日 發佈日期: 2023年03月02日

風險: 中度風險

類型: 操作系統 - LINUX

類型: LINUX

於 SUSE Linux 發現多個漏洞。攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、遠端執行程式碼及敏感資料洩露。

 

[更新於 2023-03-03] 

更新受影響、影響之系統或技術、解決方案、漏洞識別碼及相關連結。


影響

  • 阻斷服務
  • 權限提升
  • 遠端執行程式碼
  • 資料洩露

受影響之系統或技術

  • SUSE Linux Enterprise High Performance Computing 12 SP4
  • SUSE Linux Enterprise High Performance Computing 12 SP5
  • SUSE Linux Enterprise High Performance Computing 15 SP1
  • SUSE Linux Enterprise High Performance Computing 15 SP2
  • SUSE Linux Enterprise High Performance Computing 15 SP3
  • SUSE Linux Enterprise Live Patching 12-SP4
  • SUSE Linux Enterprise Live Patching 12-SP5
  • SUSE Linux Enterprise Live Patching 15-SP1
  • SUSE Linux Enterprise Live Patching 15-SP2
  • SUSE Linux Enterprise Live Patching 15-SP3
  • SUSE Linux Enterprise Micro 5.1
  • SUSE Linux Enterprise Micro 5.2
  • SUSE Linux Enterprise Server 12 SP4
  • SUSE Linux Enterprise Server 12 SP5
  • SUSE Linux Enterprise Server 15 SP1
  • SUSE Linux Enterprise Server 15 SP2
  • SUSE Linux Enterprise Server 15 SP3
  • SUSE Linux Enterprise Server for SAP Applications 12 SP4
  • SUSE Linux Enterprise Server for SAP Applications 12 SP5
  • SUSE Linux Enterprise Server for SAP Applications 15 SP1
  • SUSE Linux Enterprise Server for SAP Applications 15 SP2
  • SUSE Linux Enterprise Server for SAP Applications 15 SP3

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

WordPress 多個漏洞

WordPress 多個漏洞 發佈日期 : 2026 年 09 月 22 日 於 WordPress 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發跨網站指令碼、繞過保安限制、敏感資料洩露、遠端執行任意程式碼及資料篡改。   注意 : 針對 Word...