2023年5月10日星期三

Microsoft Monthly Security Update (May 2023)

Release Date: 10 May 2023

RISK: Medium Risk

TYPE: Operating Systems - Windows OS

TYPE: Windows OS

Microsoft has released monthly security update for their products:

 

Vulnerable ProductRisk LevelImpactsNotes
BrowserMedium Risk Medium RiskElevation of Privilege
Security Restriction Bypass
 
Microsoft OfficeMedium Risk Medium RiskInformation Disclosure
Spoofing
Remote Code Execution
Security Restriction Bypass
Denial of Service
 
WindowsMedium Risk Medium RiskRemote Code Execution
Denial of Service
Elevation of Privilege
Information Disclosure
Security Restriction Bypass

CVE-2023-29336

is being exploited in the wild.

The vulnerability can be exploited by using Win32k to trigger elevation of privilege, but this CVE is required local access and it is rated as risk medium.

 

CVE-2023-24932

is being exploited in the wild.

The vulnerability can be exploited by using Windows Secure Boot to trigger security restriction bypass, but this CVE is required local access and it is rated as risk medium.

Extended Security Updates (ESU)Medium Risk Medium RiskRemote Code Execution
Information Disclosure
Denial of Service
Elevation of Privilege
Security Restriction Bypass

CVE-2023-29336

is being exploited in the wild.

The vulnerability can be exploited by using Win32k to trigger elevation of privilege, but this CVE is required local access and it is rated as risk medium.

 

CVE-2023-24932

is being exploited in the wild.

The vulnerability can be exploited by using Windows Secure Boot to trigger security restriction bypass, but this CVE is required local access and it is rated as risk medium.

Developer ToolsMedium Risk Medium RiskInformation Disclosure
Elevation of Privilege
 

 

Number of 'Extremely High Risk' product(s): 0

Number of 'High Risk' product(s): 0

Number of 'Medium Risk' product(s): 5

Number of 'Low Risk' product(s): 0

Evaluation of overall 'Risk Level': High Risk


Impact

  • Denial of Service
  • Elevation of Privilege
  • Information Disclosure
  • Remote Code Execution
  • Spoofing
  • Security Restriction Bypass

System / Technologies affected

  • Browser
  • Microsoft Office
  • Windows
  • Extended Security Updates (ESU)
  • Developer Tools

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  •  Apply fixes issued by the vendor.

Vulnerability Identifier


Source


Related Link

2023年5月9日星期二

NetApp 產品多個漏洞

發佈日期: 2023年05月09日

風險: 中度風險

類型: 伺服器 - 其他伺服器

類型: 其他伺服器

於 NetApp 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、洩露敏感資料及資料篡改。


影響

  • 阻斷服務
  • 資料洩露
  • 篡改

受影響之系統或技術

  • Active IQ Unified Manager for Linux
  • Active IQ Unified Manager for Microsoft Windows
  • Active IQ Unified Manager for VMware vSphere
  • NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S
  • NetApp HCI Baseboard Management Controller (BMC) - H410C
  • ONTAP Select Deploy administration utilit

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝供應商提供的修補程式:

 


漏洞識別碼


資料來源


相關連結

NetApp Products Multiple Vulnerabilities

Release Date: 9 May 2023

RISK: Medium Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

Multiple vulnerabilities were identified in NetApp Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, sensitive information disclosure and data manipulation on the targeted system.


Impact

  • Denial of Service
  • Information Disclosure
  • Data Manipulation

System / Technologies affected

  • Active IQ Unified Manager for Linux
  • Active IQ Unified Manager for Microsoft Windows
  • Active IQ Unified Manager for VMware vSphere
  • NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S
  • NetApp HCI Baseboard Management Controller (BMC) - H410C
  • ONTAP Select Deploy administration utilit

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 


Vulnerability Identifier


Source


Related Link

Microsoft Edge 多個漏洞

發佈日期: 2023年05月08日

風險: 中度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Microsoft Edge 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發權限提升、遠端執行任意程式碼、洩露敏感資料及繞過保安限制。


影響

  • 遠端執行程式碼
  • 繞過保安限制
  • 資料洩露
  • 權限提升

受影響之系統或技術

  • Microsoft Edge 113.0.1774.35 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 113.0.1774.35 或之後版本

漏洞識別碼


資料來源


相關連結

Microsoft Edge Multiple Vulnerabilities

Release Date: 8 May 2023

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities were identified in Microsoft Edge. A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege, remote code execution, sensitive information disclosure and security restriction bypass on the targeted system.


Impact

  • Remote Code Execution
  • Security Restriction Bypass
  • Information Disclosure
  • Elevation of Privilege

System / Technologies affected

  • Microsoft Edge prior to 113.0.1774.35

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 113.0.1774.35 or later

Vulnerability Identifier


Source


Related Link

2023年5月5日星期五

Fortinet 產品多個漏洞

發佈日期: 2023年05月05日

風險: 中度風險

類型: 操作系統 - Network

類型: Network

於 Fortinet Products 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼、洩露敏感資料、資料篡改及繞過保安限制。

 

影響

  • 繞過保安限制
  • 資料洩露
  • 遠端執行程式碼
  • 篡改

受影響之系統或技術

  • FortiADC 5.2 所有版本 
  • FortiADC 5.3 所有版本 
  • FortiADC 5.4 所有版本 
  • FortiADC 6.0 所有版本 
  • FortiADC 6.1 所有版本 
  • FortiADC 6.2 所有版本 
  • FortiADC 7.0 所有版本 
  • FortiADC 版本 7.1.0 至 7.1.1 
  • FortiADC 版本 7.2.0 
  • FortiNAC 8.7 所有版本 
  • FortiNAC 8.8 所有版本 
  • FortiNAC 9.1 所有版本 
  • FortiNAC 9.2 所有版本  
  • FortiNAC 版本 9.4.0 至 9.4.2 
  • FortiNAC-F 版本 7.2.0 
  • FortiOS 6.0 所有版本 
  • FortiOS 版本 6.2.0 至 6.2.13 
  • FortiOS 版本 6.4.0 至 6.4.11 
  • FortiOS 版本 7.0.0 至 7.0.10 
  • FortiOS 版本 7.2.0 至 7.2.3 
  • FortiProxy 所有版本 2.0, 1.2, 1.1, 1.0 
  • FortiProxy 版本 7.0.0 至 7.0.7 
  • FortiProxy 版本 7.2.0 至 7.2.1 

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Fortinet Products Multiple Vulnerabilities

Release Date: 5 May 2023

RISK: Medium Risk

TYPE: Operating Systems - Networks OS

TYPE: Networks OS

Multiple vulnerabilities were identified in Fortinet Products. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution, sensitive information disclosure, data manipulation and security restriction bypass on the targeted system.


Impact

  • Security Restriction Bypass
  • Information Disclosure
  • Remote Code Execution
  • Data Manipulation

System / Technologies affected

  • FortiADC 5.2 all versions 
  • FortiADC 5.3 all versions 
  • FortiADC 5.4 all versions 
  • FortiADC 6.0 all versions 
  • FortiADC 6.1 all versions 
  • FortiADC 6.2 all versions 
  • FortiADC 7.0 all versions 
  • FortiADC version 7.1.0 through 7.1.1 
  • FortiADC version 7.2.0 
  • FortiNAC 8.7 all versions 
  • FortiNAC 8.8 all versions 
  • FortiNAC 9.1 all versions 
  • FortiNAC 9.2 all versions  
  • FortiNAC version 9.4.0 through 9.4.2 
  • FortiNAC-F version 7.2.0 
  • FortiOS 6.0 all versions 
  • FortiOS version 6.2.0 through 6.2.13 
  • FortiOS version 6.4.0 through 6.4.11 
  • FortiOS version 7.0.0 through 7.0.10 
  • FortiOS version 7.2.0 through 7.2.3 
  • FortiProxy all versions 2.0, 1.2, 1.1, 1.0 
  • FortiProxy version 7.0.0 through 7.0.7 
  • FortiProxy version 7.2.0 through 7.2.1 

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

2023年5月4日星期四

Google Chrome 多個漏洞

發佈日期: 2023年05月03日

風險: 中度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Google Chrome 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發資料洩露及遠端執行程式碼。

 

影響

  • 資料洩露
  • 遠端執行程式碼

受影響之系統或技術

  • Google Chrome 113.0.5672.63 (Linux) 之前的版本
  • Google Chrome 113.0.5672.63 (Mac) 之前的版本
  • Google Chrome 113.0.5672.63/.64 (Windows) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 113.0.5672.63 (Linux) 或之後版本
  • 更新至 113.0.5672.63 (Mac) 或之後版本
  • 更新至 113.0.5672.63/.64 (Windows) 或之後版本

漏洞識別碼


資料來源


相關連結

Google Chrome Multiple Vulnerabilities

Release Date: 3 May 2023

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities were identified in Google Chrome. A remote attacker could exploit some of these vulnerabilities to trigger information disclosure and remote code execution on the targeted system.


Impact

  • Information Disclosure
  • Remote Code Execution

System / Technologies affected

  • Google Chrome prior to 113.0.5672.63 (Linux)
  • Google Chrome prior to 113.0.5672.63 (Mac)
  • Google Chrome prior to 113.0.5672.63/.64 (Windows)

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 113.0.5672.63 (Linux) or later
  • Update to version 113.0.5672.63 (Mac) or later
  • Update to version 113.0.5672.63/.64 (Windows) or later

Vulnerability Identifier


Source


Related Link

三星產品多個漏洞

發佈日期: 2023年05月03日

風險: 中度風險

類型: 操作系統 - 流動裝置及操作系統

類型: 流動裝置及操作系統

於三星產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、遠端執行程式碼、繞過保安限制、篡改及洩露敏感資料。

 

注意:

CVE-2023-21492 漏洞正被廣泛利用。這個漏洞涉及內核指針記錄在日誌文件中,允許具有特權的本地攻擊者繞過ASLR。

 

影響

  • 阻斷服務
  • 權限提升
  • 資料洩露
  • 遠端執行程式碼
  • 繞過保安限制
  • 篡改

受影響之系統或技術

  • Android 11, 12, 13
  • Selected Android 11, 12, 13 Qualcomm devices
  • Select devices using Exynos CP chipsets

 

有關受影響產品,請參閱以下連結:

https://security.samsungmobile.com/securityUpdate.smsb


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。


漏洞識別碼


資料來源


相關連結

Samsung Products Multiple Vulnerabilities

Release Date: 3 May 2023

RISK: Medium Risk

TYPE: Operating Systems - Mobile & Apps

TYPE: Mobile & Apps

Multiple vulnerabilities were identified in Samsung Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, remote code execution,  security restriction bypass, data manipulation and sensitive information disclosure on the targeted system.

 

Note:

CVE-2023-21492 is being exploited in the wild. The vulnerability is related to kernel pointers printed in the log file that allows a privileged local attacker to bypass ASLR.


Impact

  • Denial of Service
  • Elevation of Privilege
  • Information Disclosure
  • Remote Code Execution
  • Security Restriction Bypass
  • Data Manipulation

System / Technologies affected

  • Android 11, 12, 13
  • Selected Android 11, 12, 13 Qualcomm devices
  • Select devices using Exynos CP chipsets

 

For affected products, please refer to the link below:

https://security.samsungmobile.com/securityUpdate.smsb


Solutions

Before installation of the software, please visit the vendor web-site for more details.


Vulnerability Identifier


Source


Related Link

2023年5月2日星期二

IBM WebSphere Application Server 資料洩露漏洞

發佈日期: 2023年05月02日

風險: 中度風險

類型: 伺服器 - 互聯網應用伺服器

類型: 互聯網應用伺服器

於 IBM WebSphere Application Server 發現一個漏洞。遠端攻擊者可利用此漏洞,於目標系統觸發洩露敏感資料。


影響

  • 資料洩露

受影響之系統或技術

  • IBM WebSphere Application Server Liberty Continuous delivery
  • IBM WebSphere Application Server 9.0 版本
  • IBM WebSphere Application Server 8.5.0.0 - 8.5.5.22 版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

IBM WebSphere Application Server Information Disclosure Vulnerability

Release Date: 2 May 2023

RISK: Medium Risk

TYPE: Servers - Internet App Servers

TYPE: Internet App Servers

A vulnerability was identified in IBM WebSphere Application Server. A remote attacker could exploit this vulnerability to trigger sensitive information disclosure on the targeted system.


Impact

  • Information Disclosure

System / Technologies affected

  • IBM WebSphere Application Server Liberty Continuous delivery
  • IBM WebSphere Application Server version 9.0
  • IBM WebSphere Application Server version 8.5.0.0 - 8.5.5.22

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Android多個漏洞

發佈日期: 2023年05月02日

風險: 中度風險

類型: 操作系統 - 流動裝置及操作系統

類型: 流動裝置及操作系統

於 Android 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升及洩露敏感資料。

 

Android Multiple Vulnerabilities

Release Date: 2 May 2023

RISK: Medium Risk

TYPE: Operating Systems - Mobile & Apps

TYPE: Mobile & Apps

Multiple vulnerabilities were identified in Android. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege and sensitive information disclosure on the targeted system.


Ubuntu Linux 核心多個漏洞

發佈日期: 2023年05月02日

風險: 中度風險

類型: 操作系統 - LINUX

類型: LINUX

於 Ubuntu 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行任意程式碼及權限提升。

 

影響

  • 阻斷服務
  • 遠端執行程式碼
  • 權限提升

受影響之系統或技術

  • Ubuntu 14.04 ESM
  • Ubuntu 16.04 ESM
  • Ubuntu 18.04 ESM
  • Ubuntu 20.04 LTS
  • Ubuntu 22.04 LTS

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Ubuntu Linux Kernel Multiple Vulnerabilities

Release Date: 2 May 2023

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities were identified in Ubuntu Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution and elevation of privilege on the targeted system.


Impact

  • Denial of Service
  • Remote Code Execution
  • Elevation of Privilege

System / Technologies affected

  • Ubuntu 14.04 ESM
  • Ubuntu 16.04 ESM
  • Ubuntu 18.04 ESM
  • Ubuntu 20.04 LTS
  • Ubuntu 22.04 LTS

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Apache Tomcat 多個漏洞

Apache Tomcat 多個漏洞 發佈日期: 2026年08月05日 風險: 中度風險 類型: 伺服器 - 網站伺服器 於 Apache T...