2025年6月11日星期三

Apache Kafka 權限提升漏洞

Apache Kafka 權限提升漏洞

發佈日期: 2025年06月11日

風險: 中度風險

類型: 伺服器 - 網站伺服器

於 Apache Kafka發現一個漏洞。遠端攻擊者可利用這個漏洞,於目標系統觸發權限提升及敏感資料洩露。

 

影響

  • 權限提升
  • 資料洩露

受影響之系統或技術

  • Apache Kafka Client 3.1.0 至 3.9.0

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:

  • Apache Kafka Client 4.0.0 版本

漏洞識別碼


資料來源


相關連結

Apache Kafka Elevation of Privilege Vulnerability

Apache Kafka Elevation of Privilege Vulnerability

Release Date: 11 Jun 2025

RISK: Medium Risk

TYPE: Servers - Web Servers

A vulnerability was identified in Apache Kafka. A remote attacker could exploit this vulnerability to trigger elevation of privilege and sensitive information disclosure on the targeted system.

 

 


Impact

  • Elevation of Privilege
  • Information Disclosure

System / Technologies affected

  • Apache Kafka Client versions 3.1.0 through 3.9.0

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:

  • Apache Kafka Client version 4.0.0

Vulnerability Identifier


Source


Related Link

Fortinet 產品多個漏洞

Fortinet 產品多個漏洞

發佈日期: 2025年06月11日

風險: 中度風險

類型: 操作系統 - Network

於 Fortinet 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發權限提升、遠端執行任意程式碼、洩露敏感資料、繞過保安限制、篡改及仿冒。


影響

  • 遠端執行程式碼
  • 資料洩露
  • 繞過保安限制
  • 篡改
  • 仿冒
  • 權限提升

受影響之系統或技術

FortiOS

  • FortiOS 6.2 所有版本
  • FortiOS 6.4 所有版本
  • FortiOS 7.0 所有版本
  • FortiOS 7.2 所有版本
  • FortiOS 7.4.0 至 7.4.7
  • FortiOS 7.6.0 至 7.6.1

FortiProxy

  • FortiProxy 1.1 所有版本
  • FortiProxy 1.2 所有版本
  • FortiProxy 2.0 所有版本
  • FortiProxy 7.0.0 至 7.0.20
  • FortiProxy 7.2.0 所有版本
  • FortiProxy 7.4.0 至 7.4.8
  • FortiProxy 7.6.0 至 7.6.2

FortiClientWindows

  • FortiClientWindows 7.0 所有版本
  • FortiClientWindows 7.2 至 7.2.6
  • FortiClientWindows 7.4.0

FortiClientEMS

  • FortiClientEMS 6.2 所有版本
  • FortiClientEMS 6.4 所有版本
  • FortiClientEMS 7.0 所有版本
  • FortiClientEMS 7.2.0 至 7.2.6
  • FortiClientEMS 7.4.0 至 7.4.1

FortiWeb

  • FortiWeb 7.4.0 至 7.4.4
  • FortiWeb 7.6.0 至 7.6.1

FortiSASE

  • FortiSASE 24.4.b
  • FortiSASE 25.1.a.2
  • FortiSASE 25.1.c

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Fortinet Products Multiple Vulnerabilities

Fortinet Products Multiple Vulnerabilities

Release Date: 11 Jun 2025

RISK: Medium Risk

TYPE: Operating Systems - Networks OS

Multiple vulnerabilities were identified in Fortinet Products. A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege, remote code execution, sensitive information disclosure, security restriction bypass, data manipulation and spoofing on the targeted system.


Impact

  • Remote Code Execution
  • Information Disclosure
  • Security Restriction Bypass
  • Data Manipulation
  • Spoofing
  • Elevation of Privilege

System / Technologies affected

FortiOS

  • FortiOS 6.2 all versions
  • FortiOS 6.4 all versions
  • FortiOS 7.0 all versions
  • FortiOS 7.2 all versions
  • FortiOS 7.4.0 through 7.4.7
  • FortiOS 7.6.0 through 7.6.1

FortiProxy

  • FortiProxy 1.1 all versions
  • FortiProxy 1.2 all versions
  • FortiProxy 2.0 all versions
  • FortiProxy 7.0.0 through 7.0.20
  • FortiProxy 7.2.0 all versions
  • FortiProxy 7.4.0 through 7.4.8
  • FortiProxy 7.6.0 through 7.6.2

FortiClientWindows

  • FortiClientWindows 7.0 all versions
  • FortiClientWindows 7.2 through 7.2.6
  • FortiClientWindows 7.4.0

FortiClientEMS

  • FortiClientEMS 6.2 all versions
  • FortiClientEMS 6.4 all versions
  • FortiClientEMS 7.0 all versions
  • FortiClientEMS 7.2.0 through 7.2.6
  • FortiClientEMS 7.4.0 through 7.4.1

FortiWeb

  • FortiWeb 7.4.0 through 7.4.6
  • FortiWeb 7.6.0 through 7.6.1

FortiSASE

  • FortiSASE 24.4.b
  • FortiSASE 25.1.a.2
  • FortiSASE 25.1.c

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Google Chrome 多個漏洞

Google Chrome 多個漏洞

發佈日期: 2025年06月11日

風險: 中度風險

類型: 用戶端 - 瀏覽器

於 Google Chrome 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況及遠端執行任意程式碼。


影響

  • 阻斷服務
  • 遠端執行程式碼

受影響之系統或技術

  • Google Chrome 137.0.7151.103 (Linux) 之前的版本
  • Google Chrome 137.0.7151.103/.104 (Mac) 之前的版本
  • Google Chrome 137.0.7151.103/.104 (Windows) 之前的版本
  • Google Chrome 137.0.7151.89 (Android) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 137.0.7151.103 (Linux) 或之後版本
  • 更新至 137.0.7151.103/.104 (Mac) 或之後版本
  • 更新至 137.0.7151.103/.104 (Windows) 或之後版本
  • 更新至 137.0.7151.89 (Android) 或之後版本

漏洞識別碼


資料來源


相關連結

Google Chrome Multiple Vulnerabilities

Google Chrome Multiple Vulnerabilities

Release Date: 11 Jun 2025

RISK: Medium Risk

TYPE: Clients - Browsers

Multiple vulnerabilities were identified in Google Chrome. A remote attacker could exploit some of these vulnerabilities to trigger denial of service and remote code execution on the targeted system.


Impact

  • Denial of Service
  • Remote Code Execution

System / Technologies affected

  • Google Chrome prior to 137.0.7151.103 (Linux)
  • Google Chrome prior to 137.0.7151.103/.104 (Mac)
  • Google Chrome prior to 137.0.7151.103/.104 (Windows)
  • Google Chrome prior to 137.0.7151.89 (Android)

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 137.0.7151.103 (Linux) or later
  • Update to version 137.0.7151.103/.104 (Mac) or later
  • Update to version 137.0.7151.103/.104 (Windows) or later
  • Update to version 137.0.7151.89 (Android) or later

Vulnerability Identifier


Source


Related Link

Mozilla 產品多個漏洞

Mozilla 產品多個漏洞

發佈日期: 2025年06月11日

風險: 中度風險

類型: 用戶端 - 瀏覽器

於 Mozilla 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務、繞過保安限制及敏感資料洩露。

 


影響

  • 資料洩露
  • 阻斷服務
  • 繞過保安限制

受影響之系統或技術

以下版本之前的版本﹕

 

  • Thunderbird 128.11.1
  • Thunderbird 139.0.2
  • Firefox 139.0.4

解決方案

在安裝軟體之前,請先瀏覽供應商之官方網站,以獲得更多詳細資料。

更新至版本:

 

  • Thunderbird 128.11.1
  • Thunderbird 139.0.2
  • Firefox 139.0.4

漏洞識別碼


資料來源


相關連結

Mozilla Products Multiple Vulnerabilities

Mozilla Products Multiple Vulnerabilities

Release Date: 11 Jun 2025

RISK: Medium Risk

TYPE: Clients - Browsers

Multiple vulnerabilities were identified in Mozilla Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, security restriction bypass and sensitive information disclosure on the targeted system.


Impact

  • Information Disclosure
  • Denial of Service
  • Security Restriction Bypass

System / Technologies affected

Versions prior to:

 

  • Thunderbird 128.11.1
  • Thunderbird 139.0.2
  • Firefox 139.0.4

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 

  • Thunderbird 128.11.1
  • Thunderbird 139.0.2
  • Firefox 139.0.4

Vulnerability Identifier


Source


Related Link

Adobe 每月保安更新 (2025年6月)

Adobe 每月保安更新 (2025年6月)

發佈日期: 2025年06月11日

風險: 中度風險

類型: 用戶端 - 辦公室應用

Adobe已為產品提供本月保安更新:

 

受影響產品風險程度影響備註詳情(包括 CVE)
Adobe InCopy中度風險 中度風險遠端執行程式碼 APSB25-41
Adobe Experience Manager中度風險 中度風險權限提升
遠端執行程式碼
跨網站指令碼
繞過保安限制
 APSB25-48
Adobe Commerce中度風險 中度風險跨網站指令碼
遠端執行程式碼
繞過保安限制
權限提升
 APSB25-50
Adobe InDesign中度風險 中度風險遠端執行程式碼
資料洩露
阻斷服務
 APSB25-53
Substance 3D Sampler中度風險 中度風險遠端執行程式碼 APSB25-55
Adobe Acrobat and Reader中度風險 中度風險遠端執行程式碼
資料洩露
阻斷服務
繞過保安限制
 APSB25-57
Substance 3D Painter中度風險 中度風險遠端執行程式碼 APSB25-58

 

「極高度風險」產品數目:0

「高度風險」產品數目:0

「中度風險」產品數目:7

「低度風險」產品數目:0

整體「風險程度」評估:中度風險


影響

  • 遠端執行程式碼
  • 權限提升
  • 跨網站指令碼
  • 繞過保安限制
  • 資料洩露
  • 阻斷服務

受影響之系統或技術

  • Adobe InCopy  20.2 及以前版本
  • Adobe InCopy  19.5.3 及以前版本
  • Adobe Experience Manager (AEM) AEM Cloud Service (CS)
  • Adobe Experience Manager (AEM) 6.5.22 及以前版本
  • Adobe Commerce 2.4.8 2.4.7-p5 及以前版本
  • Adobe Commerce B2B 1.5.2 及以前版本
  • Magento Open Source 2.4.8 2.4.7-p5 及以前版本
  • Adobe InDesign ID20.2 及以前版本
  • Adobe InDesign ID19.5.3 及以前版本
  • Adobe Substance 3D Sampler 5.0 及以前版本
  • Acrobat DC 25.001.20521 及以前版本
  • Acrobat Reader DC 25.001.20521 及以前版本
  • Acrobat 2024 24.001.30235 及以前版本
  • Acrobat 2020 20.005.30763 及以前版本
  • Acrobat Reader 2020 20.005.30763 及以前版本
  • Adobe Substance 3D Painter 11.0.1 及以前版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

  • 安裝供應商提供的修補程式。個別產品詳情可參考上表「詳情」一欄或執行軟件更新。

漏洞識別碼


資料來源


相關連結

Adobe Monthly Security Update (June 2025)

Adobe Monthly Security Update (June 2025)

Release Date: 11 Jun 2025

RISK: Medium Risk

TYPE: Clients - Productivity Products

Adobe has released monthly security update for their products:

 

Vulnerable ProductRisk LevelImpactsNotesDetails (including CVE)
Adobe InCopyMedium Risk Medium RiskRemote Code Execution APSB25-41
Adobe Experience ManagerMedium Risk Medium RiskElevation of Privilege
Remote Code Execution
Cross-site Scripting
Security Restriction Bypass
 APSB25-48
Adobe CommerceMedium Risk Medium RiskCross-site Scripting
Remote Code Execution
Security Restriction Bypass
Elevation of Privilege
 APSB25-50
Adobe InDesignMedium Risk Medium RiskRemote Code Execution
Information Disclosure
Denial of Service
 APSB25-53
Substance 3D SamplerMedium Risk Medium RiskRemote Code Execution APSB25-55
Adobe Acrobat and ReaderMedium Risk Medium RiskRemote Code Execution
Information Disclosure
Denial of Service
Security Restriction Bypass
 APSB25-57
Substance 3D PainterMedium Risk Medium RiskRemote Code Execution APSB25-58

 

Number of 'Extremely High Risk' product(s): 0

Number of 'High Risk' product(s): 0

Number of 'Medium Risk' product(s): 7

Number of 'Low Risk' product(s): 0

Evaluation of overall 'Risk Level': Medium Risk


Impact

  • Remote Code Execution
  • Elevation of Privilege
  • Cross-Site Scripting
  • Security Restriction Bypass
  • Information Disclosure
  • Denial of Service

System / Technologies affected

  • Adobe InCopy  20.2 and earlier versions
  • Adobe InCopy  19.5.3 and earlier versions
  • Adobe Experience Manager (AEM) AEM Cloud Service (CS)
  • Adobe Experience Manager (AEM) 6.5.22 and earlier versions
  • Adobe Commerce 2.4.8 2.4.7-p5 and earlier versions
  • Adobe Commerce B2B 1.5.2 and earlier versions
  • Magento Open Source 2.4.8 2.4.7-p5 and earlier versions
  • Adobe InDesign ID20.2 and earlier versions
  • Adobe InDesign ID19.5.3 and earlier versions
  • Adobe Substance 3D Sampler 5.0 and earlier versions
  • Acrobat DC 25.001.20521 and earlier versions
  • Acrobat Reader DC 25.001.20521 and earlier versions
  • Acrobat 2024 24.001.30235 and earlier versions
  • Acrobat 2020 20.005.30763 and earlier versions
  • Acrobat Reader 2020 20.005.30763 and earlier versions
  • Adobe Substance 3D Painter 11.0.1 and earlier versions

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  • Apply fixes issued by the vendor. Please refer to 'Details' column in the above table for details of individual product update or run software update.

Vulnerability Identifier


Source


Related Link

微軟每月保安更新 (2025年6月)

微軟每月保安更新 (2025年6月)

發佈日期: 2025年06月11日

風險: 極高度風險

類型: 操作系統 - 視窗操作系統

微軟已為產品提供本月保安更新:

 

受影響產品風險程度影響備註
微軟 Office中度風險 中度風險遠端執行程式碼
權限提升
 
視窗極高度風險 極高度風險遠端執行程式碼
權限提升
資料洩露
阻斷服務
繞過保安限制
仿冒

CVE-2025-33053 正被廣泛利用。此漏洞存在於 Microsoft Windows Web Distributed Authoring and Versioning。成功利用此漏洞的攻擊者可以觸發遠端執行程式碼。因此,該漏洞的風險等級被評為極高度風險。

 

CVE-2025-33073 的概念驗證碼已被公開,該漏洞影響 Windows Server Message Block(SMB)用戶端。成功利用此漏洞的授權攻擊者,可以在受影響的系統上提升權限。因此,該漏洞的風險等級被評為中度風險。

開發者工具中度風險 中度風險遠端執行程式碼
權限提升
 
延伸安全性更新 (ESU)極高度風險 極高度風險遠端執行程式碼
權限提升
資料洩露
阻斷服務
繞過保安限制

CVE-2025-33053 正被廣泛利用。此漏洞存在於 Microsoft Windows Web Distributed Authoring and Versioning。成功利用此漏洞的攻擊者可以觸發遠端執行程式碼。因此,該漏洞的風險等級被評為極高度風險。

 

CVE-2025-33073 的概念驗證碼已被公開,該漏洞影響 Windows Server Message Block(SMB)用戶端。成功利用此漏洞的授權攻擊者,可以在受影響的系統上提升權限。因此,該漏洞的風險等級被評為中度風險。

微軟 Dynamics中度風險 中度風險權限提升 
Azure低度風險 低度風險仿冒 

 

「極高度風險」產品數目:2

「高度風險」產品數目:0

「中度風險」產品數目:3

「低度風險」產品數目:1

整體「風險程度」評估:極高度風險


影響

  • 遠端執行程式碼
  • 權限提升
  • 資料洩露
  • 阻斷服務
  • 繞過保安限制
  • 仿冒

受影響之系統或技術

  • 微軟 Office
  • 視窗
  • 開發者工具
  • 延伸安全性更新 (ESU)
  • 微軟 Dynamics
  • Azure

解決方案

在安裝軟體之前,請先瀏覽軟體供應商之網站,以獲得更多詳細資料。

  • 安裝軟件供應商提供的修補程式。
 

漏洞識別碼


資料來源


相關連結

F5 BIG-IP 阻斷服務漏洞

F5 BIG-IP 阻斷服務漏洞 發佈日期 : 2026 年 09 月 21 日 風險 : 高度風險 於 F5 BIG-IP 發現一個漏洞。遠端攻擊者可利用這漏洞,於目標系統觸發阻斷服務狀況。   注意: 暫無可修補  CVE-2026-11622  的...