2024年8月14日星期三

微軟每月保安更新 (2024年8月)

發佈日期: 2024年08月14日

風險: 極高度風險

類型: 操作系統 - 視窗操作系統

微軟已為產品提供本月保安更新:

 

受影響產品風險程度影響備註
Mariner中度風險 中度風險繞過保安限制
遠端執行程式碼
 
視窗極高度風險 極高度風險繞過保安限制
資料洩露
遠端執行程式碼
權限提升
阻斷服務
篡改
仿冒

CVE-2024-38107 正在被廣泛利用。 成功利用此漏洞的攻擊者可獲得系統權限。

 

CVE-2024-38213 正在被廣泛利用。成功利用此漏洞的攻擊者可繞過 SmartScreen 使用者體驗。

 

CVE 2024 38193 正在被廣泛利用。 成功利用此漏洞的攻擊者可獲得系統權限。

 

CVE-2024-38106 正被廣泛利用。成功利用此漏洞的攻擊者若贏得競賽條件,便可獲得 SYSTEM 權限。

 

CVE-2024-38178 正被廣泛利用。如果目標在 Internet Explorer 模式下使用 Edge,成功利用此漏洞的攻擊者可啟動遠端程式碼執行。

延伸安全性更新 (ESU)極高度風險 極高度風險繞過保安限制
遠端執行程式碼
權限提升
資料洩露
阻斷服務
仿冒

CVE-2024-38107 正在被廣泛利用。 成功利用此漏洞的攻擊者可獲得系統權限。

 

CVE-2024-38213 正在被廣泛利用。成功利用此漏洞的攻擊者可繞過 SmartScreen 使用者體驗。

 

CVE 2024 38193 正在被廣泛利用。 成功利用此漏洞的攻擊者可獲得系統權限。

 

CVE-2024-38178 正被廣泛利用。如果目標在 Internet Explorer 模式下使用 Edge,成功利用此漏洞的攻擊者可啟動遠端程式碼執行

Azure中度風險 中度風險仿冒
權限提升
遠端執行程式碼
 
開發者工具中度風險 中度風險資料洩露
阻斷服務
遠端執行程式碼
 
微軟 Office極高度風險 高度風險遠端執行程式碼
仿冒
權限提升
資料洩露

CVE-2024-38189 正被廣泛利用。攻擊者可在停用封鎖從網際網路在 Office 檔案中執行巨集的原則,且未設定 VBA 巨集通知的系統上,執行遠端程式碼執行。

瀏覽器中度風險 中度風險遠端執行程式碼 
Apps低度風險 低度風險仿冒 
微軟 Dynamics低度風險 低度風險仿冒 

 

「極高度風險」產品數目:2

「高度風險」產品數目:1

「中度風險」產品數目:4

「低度風險」產品數目:2

整體「風險程度」評估:極高度風險


影響

  • 資料洩露
  • 權限提升
  • 繞過保安限制
  • 仿冒
  • 阻斷服務
  • 遠端執行程式碼
  • 篡改

受影響之系統或技術

  • Mariner
  • 視窗
  • 延伸安全性更新 (ESU)
  • Azure
  • 開發者工具
  • 微軟 Office
  • 瀏覽器
  • Apps
  • 微軟 Dynamics

解決方案

在安裝軟體之前,請先瀏覽軟體供應商之網站,以獲得更多詳細資料。

  • 安裝軟件供應商提供的修補程式。
 

漏洞識別碼


資料來源


相關連結

Microsoft Monthly Security Update (August 2024)

Release Date: 14 Aug 2024

RISK: Extremely High Risk

TYPE: Operating Systems - Windows OS

Microsoft has released monthly security update for their products:

 

Vulnerable ProductRisk LevelImpactsNotes
MarinerMedium Risk Medium RiskSecurity Restriction Bypass
Remote Code Execution
 
WindowsExtremely High Risk Extremely High RiskSecurity Restriction Bypass
Information Disclosure
Remote Code Execution
Elevation of Privilege
Denial of Service
Data Manipulation
Spoofing

CVE-2024-38107 is being exploited in the wild. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.

 

CVE-2024-38213 is being exploited in the wild.  This vulnerability can be exploited to bypass the SmartScreen user experience.

 

CVE 2024 38193 is being exploited in the wild. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.

 

CVE-2024-38106 is being exploited in the wild. An attacker who successfully exploits this vulnerability could gain SYSTEM privileges if they win a race condition.

 

CVE-2024-38178 is being exploited in the wild. An attacker who successfully exploits this vulnerability can initiate remote code execution if the target uses Edge in Internet Explorer Mode.

Extended Security Updates (ESU)Extremely High Risk Extremely High RiskSecurity Restriction Bypass
Remote Code Execution
Elevation of Privilege
Information Disclosure
Denial of Service
Spoofing

CVE-2024-38107 is being exploited in the wild. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.

 

CVE-2024-38213 is being exploited in the wild.  This vulnerability can be exploited to bypass the SmartScreen user experience.

 

CVE 2024 38193 is being exploited in the wild. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.

 

CVE-2024-38178 is being exploited in the wild. An attacker who successfully exploits this vulnerability can initiate remote code execution if the target uses Edge in Internet Explorer Mode.

AzureMedium Risk Medium RiskSpoofing
Elevation of Privilege
Remote Code Execution
 
Developer ToolsMedium Risk Medium RiskInformation Disclosure
Denial of Service
Remote Code Execution
 
Microsoft OfficeHigh Risk High RiskRemote Code Execution
Spoofing
Elevation of Privilege
Information Disclosure
CVE-2024-38189 is being exploited in the wild. An attacker who successfully exploits this vulnerability could perform remote code execution on a system where the policy to block macros from running in Office files from the Internet is disabled, and VBA Macro Notification Settings are not enabled.
BrowserMedium Risk Medium RiskRemote Code Execution 
AppsLow Risk Low RiskSpoofing 
Microsoft DynamicsLow Risk Low RiskSpoofing 

 

Number of 'Extremely High Risk' product(s): 2

Number of 'High Risk' product(s): 1

Number of 'Medium Risk' product(s): 4

Number of 'Low Risk' product(s): 2

Evaluation of overall 'Risk Level': Extremely High Risk


Impact

  • Information Disclosure
  • Elevation of Privilege
  • Security Restriction Bypass
  • Spoofing
  • Denial of Service
  • Remote Code Execution
  • Data Manipulation

System / Technologies affected

  • Mariner
  • Windows
  • Extended Security Updates (ESU)
  • Azure
  • Developer Tools
  • Microsoft Office
  • Browser
  • Apps
  • Microsoft Dynamics

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  •  Apply fixes issued by the vendor.

Vulnerability Identifier


Source


Related Link

2024年8月13日星期二

IBM WebSphere Liberty 多個漏洞

發佈日期: 2024年08月13日

風險: 中度風險

類型: 伺服器 - 網站伺服器

於 IBM WebSphere Liberty 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況,洩露敏感資料及繞過保安限制。


影響

  • 阻斷服務
  • 繞過保安限制
  • 資料洩露

受影響之系統或技術

IBM WebSphere Application Server:

 

  • 8.5
  • 9.0 

 

IBM WebSphere Application Server Liberty:

 

  • 17.0.0.3 - 24.0.0.5

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

IBM WebSphere Liberty Multiple Vulnerabilities

Release Date: 13 Aug 2024

RISK: Medium Risk

TYPE: Servers - Web Servers

Multiple vulnerabilities were identified in IBM WebSphere Liberty. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, sensitive information disclosure and security restriction bypass on the targeted system.

Impact

  • Denial of Service
  • Security Restriction Bypass
  • Information Disclosure

System / Technologies affected

IBM WebSphere Application Server:

 

  • 8.5
  • 9.0 

 

IBM WebSphere Application Server Liberty:

 

  • 17.0.0.3 - 24.0.0.5

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

GitLab 多個漏洞

發佈日期: 2024年08月12日

風險: 中度風險

類型: 伺服器 - 其他伺服器

於 GitLab 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發權限提升、繞過保安限制、跨網站指令碼、阻斷服務及資料洩露。

 

影響

  • 權限提升
  • 繞過保安限制
  • 跨網站指令碼
  • 阻斷服務
  • 資料洩露

受影響之系統或技術

  • GitLab Community Edition (CE) 17.2.2, 17.1.4 及 17.0.6 以前的版本
  • GitLab Enterprise Edition (EE) 17.2.2, 17.1.4 及 17.0.6 以前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

GitLab Multiple Vulnerabilities

Release Date: 12 Aug 2024

RISK: Medium Risk

TYPE: Servers - Other Servers

Multiple vulnerabilities were identified in GitLab. A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege, security restriction bypass, cross-site scripting, denial of service and information disclosure on the targeted system.


Impact

  • Elevation of Privilege
  • Security Restriction Bypass
  • Cross-Site Scripting
  • Denial of Service
  • Information Disclosure

System / Technologies affected

  • GitLab Community Edition (CE) versions prior to 17.2.2, 17.1.4 and 17.0.6
  • GitLab Enterprise Edition (EE) versions prior to 17.2.2, 17.1.4 and 17.0.6

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

2024年8月10日星期六

Jenkins 多個漏洞

發佈日期: 2024年08月09日

風險: 中度風險

類型: 操作系統 - 流動裝置及操作系統

於 Jenkins 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發權限提升及遠端執行任意程式碼。


影響

  • 遠端執行程式碼
  • 權限提升

受影響之系統或技術

  • Jenkins weekly 2.470 及以前的版本
  • Jenkins LTS 2.452.3 及以前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝供應商提供的修補程式:

 


漏洞識別碼


資料來源


相關連結

Jenkins Multiple Vulnerabilities

Release Date: 9 Aug 2024

RISK: Medium Risk

TYPE: Operating Systems - Mobile & Apps

Multiple vulnerabilities were identified in Jenkins. A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege and remote code execution on the targeted system.


Impact

  • Remote Code Execution
  • Elevation of Privilege

System / Technologies affected

  • Jenkins weekly up to and including 2.470
  • Jenkins LTS up to and including 2.452.3

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 


Vulnerability Identifier


Source


Related Link

Microsoft Edge 多個漏洞

發佈日期: 2024年08月09日

風險: 中度風險

類型: 用戶端 - 瀏覽器

於 Microsoft Edge 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行任意程式碼及洩露敏感資料。


Microsoft Edge Multiple Vulnerabilities

Release Date: 9 Aug 2024

RISK: Medium Risk

TYPE: Clients - Browsers

Multiple vulnerabilities were identified in Microsoft Edge. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution and sensitive information disclosure on the targeted system.


2024年8月8日星期四

Microsoft Windows 多個漏洞

發佈日期: 2024年08月08日

風險: 中度風險

類型: 操作系統 - 視窗操作系統

於 Microsoft Windows 發現多個漏洞,攻擊者可利用這些漏洞,於目標系統觸發權限提升、洩露敏感資料及資料篡改。

 

注意:

目前沒有適用於受影響產品的 CVE-2024-21302 和 CVE-2024-38202 的修補程式或緩解措施。

對於CVE-2024-21302,在目標系統上擁有管理員權限的攻擊者可能會用過時的版本取代目前的Windows系統檔案。

對於 CVE-2024-38202,攻擊者可能會欺騙或說服管理員或具有委派權限的使用者執行系統還原,從而無意中觸發權限提升。


影響

  • 權限提升
  • 資料洩露
  • 篡改

受影響之系統或技術

  • Windows Server 2016 (Server Core installation)
  • Windows Server 2016
  • Windows 10 Version 1607 for x64-based Systems
  • Windows 10 Version 1607 for 32-bit Systems
  • Windows 10 for x64-based Systems
  • Windows 10 for 32-bit Systems
  • Windows 11 Version 24H2 for x64-based Systems
  • Windows 11 Version 24H2 for ARM64-based Systems
  • Windows Server 2022, 23H2 Edition (Server Core installation)
  • Windows 11 Version 23H2 for x64-based Systems
  • Windows 11 Version 23H2 for ARM64-based Systems
  • Windows 10 Version 22H2 for 32-bit Systems
  • Windows 10 Version 22H2 for ARM64-based Systems
  • Windows 10 Version 22H2 for x64-based Systems
  • Windows 11 Version 22H2 for x64-based Systems
  • Windows 11 Version 22H2 for ARM64-based Systems
  • Windows 10 Version 21H2 for x64-based Systems
  • Windows 10 Version 21H2 for ARM64-based Systems
  • Windows 10 Version 21H2 for 32-bit Systems
  • Windows 11 version 21H2 for ARM64-based Systems
  • Windows 11 version 21H2 for x64-based Systems
  • Windows Server 2022 (Server Core installation)
  • Windows Server 2022
  • Windows Server 2019 (Server Core installation)
  • Windows Server 2019
  • Windows 10 Version 1809 for ARM64-based Systems
  • Windows 10 Version 1809 for x64-based Systems
  • Windows 10 Version 1809 for 32-bit Systems

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

 

解決方案步驟:

 

 


漏洞識別碼


資料來源


相關連結

F5 BIG-IP 阻斷服務漏洞

F5 BIG-IP 阻斷服務漏洞 發佈日期 : 2026 年 09 月 21 日 風險 : 高度風險 於 F5 BIG-IP 發現一個漏洞。遠端攻擊者可利用這漏洞,於目標系統觸發阻斷服務狀況。   注意: 暫無可修補  CVE-2026-11622  的...