2024年5月17日星期五

Fortinet Products Multiple Vulnerabilities

Release Date: 17 May 2024

RISK: Medium Risk

TYPE: Operating Systems - Networks OS

TYPE: Networks OS

Multiple vulnerabilities were identified in Fortinet Products. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution, denial of service, elevation of privilege and security restriction bypass on the targeted system.

 


Impact

  • Security Restriction Bypass
  • Remote Code Execution
  • Elevation of Privilege
  • Denial of Service

System / Technologies affected

  • FortiOS version 7.4.0 through 7.4.1
  • FortiOS version 7.2.0 through 7.2.7
  • FortiOS version 7.0.0 through 7.0.12
  • FortiOS 6.4 all versions
  • FortiOS 6.2 all versions
  • FortiOS version 6.0.0 through 6.0.16
  • FortiWeb version 7.4.0 through 7.4.2
  • FortiWeb version 7.2.0 through 7.2.7
  • FortiWeb 7.0 all versions
  • FortiWeb 6.4 all versions
  • FortiWeb 6.3 all versions
  • FortiNAC version 9.4.0 through 9.4.4
  • FortiNAC 9.2 all versions
  • FortiNAC 9.1 all versions
  • FortiNAC 8.8 all versions
  • FortiNAC 8.7 all versions
  • FortiNAC version 7.2.0 through 7.2.3
  • FortiProxy version 7.4.0 through 7.4.1
  • FortiProxy version 7.2.0 through 7.2.7
  • FortiProxy version 7.0.0 through 7.0.13
  • FortiProxy 2.0 all versions
  • FortiProxy 1.2 all versions
  • FortiProxy 1.1 all versions
  • FortiProxy 1.0 all versions
  • FortiWebManager version 7.2.0
  • FortiWebManager version 7.0.0 through 7.0.4
  • FortiWebManager version 6.3.0
  • FortiWebManager version 6.2.3 through 6.2.4
  • FortiWebManager version 6.0.2
  • FortiAuthenticator version 6.6.0
  • FortiAuthenticator version 6.5.0 through 6.5.3
  • FortiAuthenticator 6.4 all versions
  • FortiSwitchManager version 7.2.0 through 7.2.2
  • FortiSwitchManager version 7.0.0 through 7.0.2

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Google Chrome 遠端執行程式碼漏洞

發佈日期: 2024年05月17日

風險: 極高度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Google Chrome 發現一個漏洞。遠端攻擊者可利用這個漏洞,於目標系統觸發遠端執行任意程式碼及阻斷服務。

 

注意:

Google 已知悉 CVE-2024-4761 已被廣泛利用。CVE-2024-4761 是一個影響 V8 Javascript 和 WebAssembly 引擎的越界寫入漏洞,可以導致阻斷服務狀況或在受感染主機上執行任意程式碼。

 

影響

  • 遠端執行程式碼
  • 阻斷服務

受影響之系統或技術

  • Google Chrome 124.0.6367.207 (Linux) 之前的版本
  • Google Chrome 124.0.6367.207/.208 (Mac) 之前的版本
  • Google Chrome 124.0.6367.207/.208 (Windows) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 124.0.6367.207 (Linux) 或之後版本
  • 更新至 124.0.6367.207/.208 (Mac) 或之後版本
  • 更新至 124.0.6367.207/.208 (Windows) 或之後版本

漏洞識別碼


資料來源


相關連結

Google Chrome Remote Code Execution Vulnerability

Release Date: 17 May 2024

RISK: Extremely High Risk

TYPE: Clients - Browsers

TYPE: Browsers

A vulnerability was identified in Google Chrome. A remote attacker could exploit this vulnerability to trigger remote code execution and denial of service on the targeted system.

 

Note:

Google is aware of reports that an exploit for CVE-2024-4761 exists in the wild. CVE-2024-4761 is an out-of-bounds write vulnerability impacting the V8 Javascript and WebAssembly engine leading to crash condition or arbitrary code execution on compromised hosts. 


Impact

  • Remote Code Execution
  • Denial of Service

System / Technologies affected

  • Google Chrome prior to 124.0.6367.207 (Linux)
  • Google Chrome prior to 124.0.6367.207/.208 (Mac)
  • Google Chrome prior to 124.0.6367.207/.208 (Windows)

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 124.0.6367.207 (Linux) or later
  • Update to version 124.0.6367.207/.208 (Mac) or later
  • Update to version 124.0.6367.207/.208 (Windows) or later

Vulnerability Identifier


Source


Related Link

2024年5月16日星期四

Adobe 每月保安更新 (2024年5月)

發佈日期: 2024年05月16日

風險: 中度風險

類型: 用戶端 - 辦公室應用

類型: 辦公室應用

Adobe已為產品提供本月保安更新:

 

受影響產品風險程度影響備註詳情(包括 CVE)
Adobe Acrobat and Reader中度風險 中度風險遠端執行程式碼
資料洩露
 APSB24-29
Adobe Illustrator中度風險 中度風險遠端執行程式碼
資料洩露
 APSB24-30
Adobe Substance 3D Painter中度風險 中度風險遠端執行程式碼
資料洩露
 APSB24-31
Adobe Aero中度風險 中度風險遠端執行程式碼 APSB24-33
Adobe Substance 3D Designer中度風險 中度風險資料洩露 APSB24-35
Adobe Animate中度風險 中度風險遠端執行程式碼
資料洩露
 APSB24-36
Adobe Framemaker中度風險 中度風險遠端執行程式碼
資料洩露
 APSB24-37
Adobe Dreamweaver 中度風險 中度風險遠端執行程式碼 APSB24-39

 

「極高度風險」產品數目:0

「高度風險」產品數目:0

「中度風險」產品數目:8

「低度風險」產品數目:0

整體「風險程度」評估:中度風險

 

影響

  • 遠端執行程式碼
  • 資料洩露

受影響之系統或技術

  • Acrobat DC 24.002.20736 及以前版本
  • Acrobat Reader DC 24.002.20736 及以前版本
  • Acrobat 2020 20.005.30574 及以前版本
  • Acrobat Reader 2020 20.005.30574 及以前版本
  • Illustrator 2024 28.4 及以前版本
  • Illustrator 2023 27.9.3 及以前版本
  • Adobe Substance 3D Painter 9.1.2 及以前版本
  • Aero 0.23.4 及以前版本
  • Adobe Substance 3D Designer 13.1.1 及以前版本
  • Adobe Animate 2023 23.0.5 及以前版本
  • Adobe Animate 2024 24.0.2 及以前版本
  • Adobe FrameMaker 2020 Release Update 5 及以前版本
  • Adobe FrameMaker 2022 Release Update 3 及以前版本
  • Adobe Dreamweaver  21.3 及以前版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

  • 安裝供應商提供的修補程式。個別產品詳情可參考上表「詳情」一欄或執行軟件更新。

漏洞識別碼


資料來源


相關連結

Adobe Monthly Security Update (May 2024)

Release Date: 16 May 2024

RISK: Medium Risk

TYPE: Clients - Productivity Products

TYPE: Productivity Products

Adobe has released monthly security update for their products:

 

Vulnerable ProductRisk LevelImpactsNotesDetails (including CVE)
Adobe Acrobat and ReaderMedium Risk Medium RiskRemote Code Execution
Information Disclosure
 APSB24-29
Adobe IllustratorMedium Risk Medium RiskRemote Code Execution
Information Disclosure
 APSB24-30
Adobe Substance 3D PainterMedium Risk Medium RiskRemote Code Execution
Information Disclosure
 APSB24-31
Adobe AeroMedium Risk Medium RiskRemote Code Execution APSB24-33
Adobe Substance 3D DesignerMedium Risk Medium RiskInformation Disclosure APSB24-35
Adobe AnimateMedium Risk Medium RiskRemote Code Execution
Information Disclosure
 APSB24-36
Adobe FramemakerMedium Risk Medium RiskRemote Code Execution
Information Disclosure
 APSB24-37
Adobe Dreamweaver Medium Risk Medium RiskRemote Code Execution APSB24-39

 

Number of 'Extremely High Risk' product(s): 0

Number of 'High Risk' product(s): 0

Number of 'Medium Risk' product(s): 8

Number of 'Low Risk' product(s): 0

Evaluation of overall 'Risk Level': Medium Risk

 

Impact

  • Remote Code Execution
  • Information Disclosure

System / Technologies affected

  • Acrobat DC 24.002.20736 and earlier versions
  • Acrobat Reader DC 24.002.20736 and earlier versions
  • Acrobat 2020 20.005.30574 and earlier versions
  • Acrobat Reader 2020 20.005.30574 and earlier versions
  • Illustrator 2024 28.4 and earlier versions
  • Illustrator 2023 27.9.3 and earlier versions
  • Adobe Substance 3D Painter 9.1.2 and earlier versions
  • Aero 0.23.4 and earlier versions
  • Adobe Substance 3D Designer 13.1.1 and earlier versions
  • Adobe Animate 2023 23.0.5 and earlier versions
  • Adobe Animate 2024 24.0.2 and earlier versions
  • Adobe FrameMaker 2020 Release Update 5 and earlier versions
  • Adobe FrameMaker 2022 Release Update 3 and earlier versions
  • Adobe Dreamweaver  21.3 and earlier versions

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  • Apply fixes issued by the vendor. Please refer to 'Details' column in the above table for details of individual product update or run software update

Vulnerability Identifier


Source


Related Link

Aruba 產品多個漏洞

發佈日期: 2024年05月16日

風險: 中度風險

類型: 保安軟件及應用設備 - 保安軟件及應用設備

類型: 保安軟件及應用設備

在Aruba產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發權限提升、洩露敏感資料、阻斷服務狀況及遠端執行任意程式碼。

 

影響

  • 遠端執行程式碼
  • 資料洩露
  • 權限提升
  • 阻斷服務

受影響之系統或技術

  • ArubaOS 10.5.1.0及之前版本
  • ArubaOS 10.4.1.0 及之前版本
  • InstantOS 8.11.2.1 及之前版本
  • InstantOS 8.10.0.10 及之前版本
  • InstantOS 8.6.0.24 及之前版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Aruba Products Multiple Vulnerabilities

Release Date: 16 May 2024

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

Multiple vulnerabilities were identified in Aruba Products. A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege, sensitive information disclosure, denial of service condition and remote code execution on the targeted system.


Impact

  • Remote Code Execution
  • Information Disclosure
  • Elevation of Privilege
  • Denial of Service

System / Technologies affected

  • ArubaOS 10.5.1.0 and below
  • ArubaOS 10.4.1.0 and below
  • InstantOS 8.11.2.1 and below
  • InstantOS 8.10.0.10 and below
  • InstantOS 8.6.0.24 and below

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

F5 產品多個漏洞

發佈日期: 2024年05月16日

風險: 高度風險

類型: 操作系統 - Network

類型: Network

於 F5 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、資料洩露及資料篡改。

 

注意:

暫無可修補 CVE-2022-40304 的修補程式。

暫無臨時處理方法和可修補 CVE-2023-29469 的修補程式。


影響

  • 阻斷服務
  • 資料洩露
  • 篡改

受影響之系統或技術

BIG-IP (AFM, Analytics, AAM, DNS, FPS, Link Controller, LTM, PEM, Advanced WAF, ASM)

  • 15.1.0 - 15.1.10
  • 16.1.0 - 16.1.4
  • 17.1.0 - 17.1.1

 

BIG-IQ Centralized Management

  • 8.1.0 - 8.3.0

 

Traffix SDC

  • 5.1.0

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:

 

應用供應商提供的臨時處理方法:

 

臨時處理方法:

跟從以下CVE-2022-40304的臨時處理方法以減少攻擊:

  • 不允許在 XML 設定檔中進行文件類型定義 (DTD) 驗證,也不允許在包含自訂 XML 的監視器或 iRules 中進行 DTD 驗證。


漏洞識別碼


資料來源


相關連結

F5 Products Multiple Vulnerabilities

Release Date: 16 May 2024

RISK: High Risk

TYPE: Operating Systems - Networks OS

TYPE: Networks OS

Multiple vulnerabilities were identified in F5 Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, information disclosure and data manipulation on the targeted system.

 

Note:

No patch is currently available for CVE-2022-40304 of the affected products.

No patch and workaround is currently available for CVE-2023-29469 of the affected products.


Impact

  • Denial of Service
  • Information Disclosure
  • Data Manipulation

System / Technologies affected

BIG-IP (AFM, Analytics, AAM, DNS, FPS, Link Controller, LTM, PEM, Advanced WAF, ASM)

  • 15.1.0 - 15.1.10
  • 16.1.0 - 16.1.4
  • 17.1.0 - 17.1.1

 

BIG-IQ Centralized Management

  • 8.1.0 - 8.3.0

 

Traffix SDC

  • 5.1.0

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:

 

Apply workarounds issued by the vendor:

 

Workaround:

Reduce the vulnerability of attacks of CVE-2022-40304 by following workaround:

  • Do not allow Document Type Definition (DTD) validation in XML profiles or permit DTD validation in monitors or iRules that contain custom XML.


Vulnerability Identifier


Source


Related Link

Google Chrome 多個漏洞

發佈日期: 2024年05月16日

風險: 極高度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Google Chrome 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發彷冒、遠端執行任意程式碼及阻斷服務狀況。

 

注意:

CVE-2024-4947 正在被廣泛利用。 CVE-2024-4947 是由 Chrome V8 JavaScript 引擎中的漏洞引起,可以導致在目標裝置上遠端執行程式碼。

 

影響

  • 遠端執行程式碼
  • 仿冒
  • 阻斷服務

受影響之系統或技術

  • Google Chrome 124.0.6422.60 (Linux) 之前的版本
  • Google Chrome 125.0.6422.60/.61 (Mac) 之前的版本
  • Google Chrome 125.0.6422.60/.61 (Windows) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 124.0.6422.60 (Linux) 或之後版本
  • 更新至 125.0.6422.60/.61 (Mac) 或之後版本
  • 更新至 125.0.6422.60/.61 (Windows) 或之後版本

漏洞識別碼


資料來源


相關連結

Google Chrome Multiple Vulnerabilities

Release Date: 16 May 2024

RISK: Extremely High Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities were identified in Google Chrome. A remote attacker could exploit some of these vulnerabilities to trigger spoofing, remote code execution and denial of service condition on the targeted system.

 

Notes:

CVE-2024-4947 are being exploited in the wild. CVE-2024-4947 is casued by a type confusion weakness in the Chrome V8 JavaScript engine and can lead to remote code execution on targeted device. 


Impact

  • Remote Code Execution
  • Spoofing
  • Denial of Service

System / Technologies affected

  • Google Chrome prior to 124.0.6422.60 (Linux)
  • Google Chrome prior to 125.0.6422.60/.61 (Mac)
  • Google Chrome prior to 125.0.6422.60/.61 (Windows)

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 124.0.6422.60 (Linux) or later
  • Update to version 125.0.6422.60/.61 (Mac) or later
  • Update to version 125.0.6422.60/.61 (Windows) or later

Vulnerability Identifier


Source


Related Link

F5 BIG-IP 遠端執行程式碼漏洞

F5 BIG-IP 遠端執行程式碼漏洞 發佈日期 : 2026 年 09 月 23 日 於 F5 BIG-IP 發現一個漏洞。遠端攻擊者可利用這漏洞,於目標系統觸發遠端執行程式碼狀況。   注意: CVE-2026-94127 正被廣泛利用。此漏洞僅在 B...