2023年11月15日星期三

ChromeOS 多個漏洞

發佈日期: 2023年11月15日

風險: 中度風險

類型: 操作系統 - 其他操作系統

類型: 其他操作系統

於 ChromeOS 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行任意程式碼及繞過保安限制。


影響

  • 遠端執行程式碼
  • 阻斷服務
  • 繞過保安限制

受影響之系統或技術

  • 119.0.6045.158 (平台版本: 15633.44.0) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式,詳情請參閱以下連結:


漏洞識別碼


資料來源


相關連結

ChromeOS Multiple Vulnerabilities

Release Date: 15 Nov 2023

RISK: Medium Risk

TYPE: Operating Systems - Others OS

TYPE: Others OS

Multiple vulnerabilities were identified in ChromeOS. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution and security restriction bypass on the targeted system.


Impact

  • Remote Code Execution
  • Denial of Service
  • Security Restriction Bypass

System / Technologies affected

  • Version prior to 119.0.6045.158 (Platform Version: 15633.44.0)

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor. For detail, please refer to the link below:


Vulnerability Identifier


Source


Related Link

Google Chrome 遠端執行任意程式碼漏洞

發佈日期: 2023年11月15日

風險: 中度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Google Chrome 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼。


影響

  • 遠端執行程式碼

受影響之系統或技術

  • Google Chrome 119.0.6045.163 (Android) 之前的版本
  • Google Chrome 119.0.6045.159 (Linux) 之前的版本
  • Google Chrome 119.0.6045.159 (Mac) 之前的版本
  • Google Chrome 119.0.6045.159/.160 (Windows) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 119.0.6045.163 (Android) 或之後版本
  • 更新至 119.0.6045.159 (Linux) 或之後版本
  • 更新至 119.0.6045.159 (Mac) 或之後版本
  • 更新至 119.0.6045.159 (Windows) 或之後版本

漏洞識別碼


資料來源


相關連結

Google Chrome Remote Code Execution Vulnerabilities

Release Date: 15 Nov 2023

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities were identified in Google Chrome.  A remote attacker could exploit some of these vulnerabilities to trigger remote code execution on the targeted system.


Impact

  • Remote Code Execution

System / Technologies affected

  • Google Chrome prior to 119.0.6045.163 (Android)
  • Google Chrome prior to 119.0.6045.159 (Linux)
  • Google Chrome prior to 119.0.6045.159 (Mac)
  • Google Chrome prior to 119.0.6045.159/.160 (Windows)

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 119.0.6045.163 (Android) or later
  • Update to version 119.0.6045.159 (Linux) or later
  • Update to version 119.0.6045.159 (Mac) or later
  • Update to version 119.0.6045.159/.160 (Windows) or later

Vulnerability Identifier


Source


Related Link

微軟每月保安更新 (2023年11月)

發佈日期: 2023年11月15日

風險: 高度風險

類型: 操作系統 - 視窗操作系統

類型: 視窗操作系統

微軟已為產品提供本月保安更新:

 

受影響產品風險程度影響備註
瀏覽器中度風險 中度風險遠端執行程式碼
權限提升
仿冒
 
Azure中度風險 中度風險遠端執行程式碼
資料洩露
繞過保安限制
 
視窗高度風險 高度風險權限提升
資料洩露
遠端執行程式碼
阻斷服務
仿冒
繞過保安限制

CVE-2023-36025 正被廣泛利用。 此漏洞允許惡意網路捷徑繞過安全檢查和警告。

 

CVE-2023-36033 正被廣泛利用。此漏洞可被利用以獲得 SYSTEM 權限。

 

CVE-2023-36036 正被廣泛利用。此漏洞可被利用以獲得 SYSTEM 權限。

延伸安全性更新 (ESU)高度風險 高度風險權限提升
資料洩露
遠端執行程式碼
阻斷服務
繞過保安限制

CVE-2023-36025 正被廣泛利用。 此漏洞允許惡意網路捷徑繞過安全檢查和警告。

 

CVE-2023-36033 正被廣泛利用。此漏洞可被利用以獲得 SYSTEM 權限。

 

CVE-2023-36036 正被廣泛利用。此漏洞可被利用以獲得 SYSTEM 權限。

開發者工具中度風險 中度風險繞過保安限制
權限提升
阻斷服務
仿冒
 
System Center中度風險 中度風險權限提升
資料洩露
 
微軟 Office中度風險 中度風險繞過保安限制
遠端執行程式碼
 
微軟 Dynamics低度風險 低度風險仿冒 
Exchange Server中度風險 中度風險遠端執行程式碼
仿冒
 
Mariner低度風險 低度風險阻斷服務 

 

「極高度風險」產品數目:0

「高度風險」產品數目:2

「中度風險」產品數目:6

「低度風險」產品數目:2

整體「風險程度」評估:高度風險


影響

  • 遠端執行程式碼
  • 阻斷服務
  • 權限提升
  • 資料洩露
  • 繞過保安限制
  • 仿冒

受影響之系統或技術

  • 瀏覽器
  • 視窗
  • 延伸安全性更新 (ESU)
  • 開發者工具
  • Azure
  • 微軟 Office
  • SQL Server
  • 微軟 Dynamics
  • Exchange Server
  • Mariner

解決方案

在安裝軟體之前,請先瀏覽軟體供應商之網站,以獲得更多詳細資料。

  • 安裝軟件供應商提供的修補程式。
 

漏洞識別碼


資料來源


相關連結

Microsoft Monthly Security Update (November 2023)

Release Date: 15 Nov 2023

RISK: High Risk

TYPE: Operating Systems - Windows OS

TYPE: Windows OS

Microsoft has released monthly security update for their products:

 

Vulnerable ProductRisk LevelImpactsNotes
BrowserMedium Risk Medium RiskRemote Code Execution
Elevation of Privilege
Spoofing
 
AzureMedium Risk Medium RiskRemote Code Execution
Information Disclosure
Security Restriction Bypass
 
WindowsHigh Risk High RiskElevation of Privilege
Information Disclosure
Remote Code Execution
Denial of Service
Spoofing
Security Restriction Bypass

CVE-2023-36025 is being exploited in the wild. The vulnerability allows a malicious internet shortcut to bypass secuirty checks and warnings.

 

CVE-2023-36033 is being exploited in the wild. The vulnerability can be expoloited to gain SYSTEM privileges. 

 

CVE-2023-36036 is being exploited in the wild. The vulnerability can be exploited to gain SYSTEM privileges. 

 

Extended Security Updates (ESU)

High Risk High RiskElevation of Privilege
Information Disclosure
Remote Code Execution
Denial of Service
Security Restriction Bypass

CVE-2023-36025 is being exploited in the wild. The vulnerability allows a malicious internet shortcut to bypass secuirty checks and warnings.

 

CVE-2023-36033 is being exploited in the wild. The vulnerability can be expoloited to gain SYSTEM privileges. 

 

CVE-2023-36036 is being exploited in the wild. The vulnerability can be exploited to gain SYSTEM privileges. 

Developer ToolsMedium Risk Medium RiskSecurity Restriction Bypass
Elevation of Privilege
Denial of Service
Spoofing
 
System CenterMedium Risk Medium RiskElevation of Privilege
Information Disclosure
 
Microsoft OfficeMedium Risk Medium RiskSecurity Restriction Bypass
Remote Code Execution
 
Microsoft DynamicsLow Risk Low RiskSpoofing 
Exchange ServerMedium Risk Medium RiskRemote Code Execution
Spoofing
 
MarinerLow Risk Low RiskDenial of Service 

 

Number of 'Extremely High Risk' product(s): 0

Number of 'High Risk' product(s): 2

Number of 'Medium Risk' product(s): 6

Number of 'Low Risk' product(s): 2

Evaluation of overall 'Risk Level': High Risk


Impact

  • Remote Code Execution
  • Denial of Service
  • Elevation of Privilege
  • Information Disclosure
  • Security Restriction Bypass
  • Spoofing

System / Technologies affected

  • Browser
  • Windows
  • Extended Security Updates (ESU)
  • Developer Tools
  • Azure
  • Microsoft Office
  • SQL Server
  • Microsoft Dynamics
  • Exchange Server
  • Mariner

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  •  Apply fixes issued by the vendor.

Vulnerability Identifier


Source


Related Link

SAP 產品多個漏洞

發佈日期: 2023年11月15日

風險: 中度風險

類型: 用戶端 - 辦公室應用

類型: 辦公室應用

於 SAP 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼、洩露敏感資料及繞過保安限制。


影響

  • 遠端執行程式碼
  • 繞過保安限制
  • 資料洩露

受影響之系統或技術

詳情請參閱以下連結﹕


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

SAP Products Multiple Vulnerabilities

Release Date: 15 Nov 2023

RISK: Medium Risk

TYPE: Clients - Productivity Products

TYPE: Productivity Products

Multiple vulnerabilities were identified in SAP Products. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution, sensitive information disclosure, and security restriction bypass on the targeted system.


Impact

  • Remote Code Execution
  • Security Restriction Bypass
  • Information Disclosure

System / Technologies affected

Please refer to the link below for detail:


Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

NetApp 產品阻斷服務狀況漏洞

發佈日期: 2023年11月14日

風險: 中度風險

類型: 伺服器 - 其他伺服器

類型: 其他伺服器

於 NetApp 產品發現一個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、洩露敏感資料及資料篡改。

 

影響

  • 阻斷服務
  • 篡改
  • 資料洩露

受影響之系統或技術

  • NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S
 

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝供應商提供的修補程式:

 


漏洞識別碼


資料來源


相關連結

NetApp Denial of Service Vulnerability

Release Date: 14 Nov 2023

RISK: Medium Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

A vulnerability was identified in a NetApp Product. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, sensitive information disclosure and data manipulation on the targeted system.


Impact

  • Denial of Service
  • Data Manipulation
  • Information Disclosure

System / Technologies affected

  • NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S
 

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 


Vulnerability Identifier


Source


Related Link

OpenVPN 產品多個漏洞

發佈日期: 2023年11月14日

風險: 中度風險

類型: 伺服器 - 其他伺服器

類型: 其他伺服器

於 OpenVPN 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況及洩露敏感資料。

 

影響

  • 阻斷服務
  • 資料洩露

受影響之系統或技術

  • OpenVPN Access Server versions 2.11.0, 2.11.1, 2.11.2, 2.11.3, 2.12.0, and 2.12.1
 

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝供應商提供的修補程式:

 


漏洞識別碼


資料來源


相關連結

OpenVPN Multiple Vulnerabilities

Release Date: 14 Nov 2023

RISK: Medium Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

Multiple vulnerabilities were identified in OpenVPN. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition and sensitive information disclosure on the targeted system.


Impact

  • Denial of Service
  • Information Disclosure

System / Technologies affected

  • OpenVPN Access Server versions 2.11.0, 2.11.1, 2.11.2, 2.11.3, 2.12.0, and 2.12.1

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 


Vulnerability Identifier


Source


Related Link

2023年11月13日星期一

Microsoft Edge 多個漏洞

發佈日期: 2023年11月10日

風險: 中度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Microsoft Edge 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發權限提升、遠端執行任意程式碼及阻斷服務狀況。

 

影響

  • 阻斷服務
  • 遠端執行程式碼
  • 權限提升

受影響之系統或技術

  • Microsoft Edge 119.0.2151.58 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 119.0.2151.58 或之後版本

漏洞識別碼


資料來源


相關連結

Microsoft Edge Multiple Vulnerabilities

Release Date: 10 Nov 2023

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities were identified in Microsoft Edge. A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege, remote code execution and denial of service condition on the targeted system.


Impact

  • Denial of Service
  • Remote Code Execution
  • Elevation of Privilege

System / Technologies affected

  • Microsoft Edge prior to 119.0.2151.58

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 119.0.2151.58 or later

Vulnerability Identifier


Source


Related Link

2023年11月8日星期三

Android多個漏洞

發佈日期: 2023年11月08日

風險: 中度風險

類型: 操作系統 - 流動裝置及操作系統

類型: 流動裝置及操作系統

於 Android 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升及洩露敏感資料。


影響

  • 阻斷服務
  • 權限提升
  • 資料洩露

受影響之系統或技術

  • 2023-11-05 前的 Android 保安更新級別

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。


漏洞識別碼


資料來源


相關連結

Android Multiple Vulnerabilities

Release Date: 8 Nov 2023

RISK: Medium Risk

TYPE: Operating Systems - Mobile & Apps

TYPE: Mobile & Apps

Multiple vulnerabilities were identified in Android. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege and sensitive information disclosure on the targeted system.


Impact

  • Denial of Service
  • Elevation of Privilege
  • Information Disclosure

System / Technologies affected

  • Android security patch level prior to 2023-11-05

Solutions

Before installation of the software, please visit the vendor web-site for more details.


Vulnerability Identifier


Source


Related Link

ChromeOS 多個漏洞

發佈日期: 2023年11月08日

風險: 中度風險

類型: 操作系統 - 其他操作系統

類型: 其他操作系統

於 ChromeOS 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行任意程式碼及繞過保安限制。


影響

  • 遠端執行程式碼
  • 阻斷服務
  • 繞過保安限制

受影響之系統或技術

  • 114.0.5735.339 (平台版本: 15437.76.0) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式,詳情請參閱以下連結:


漏洞識別碼


資料來源


相關連結

ChromeOS Multiple Vulnerabilities

Release Date: 8 Nov 2023

RISK: Medium Risk

TYPE: Operating Systems - Others OS

TYPE: Others OS

Multiple vulnerabilities were identified in ChromeOS. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution and security restriction bypass on the targeted system.


Impact

  • Remote Code Execution
  • Denial of Service
  • Security Restriction Bypass

System / Technologies affected

  • Version prior to 114.0.5735.339 (Platform Version: 15437.76.0)

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor. For detail, please refer to the link below:


Vulnerability Identifier


Source


Related Link

Google Chrome 遠端執行程式碼漏洞

發佈日期: 2023年11月08日

風險: 中度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Google Chrome 發現一個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升及遠端執行任意程式碼。


影響

  • 遠端執行程式碼
  • 阻斷服務
  • 權限提升

受影響之系統或技術

  • Google Chrome 119.0.6045.123 (Linux) 之前的版本
  • Google Chrome 119.0.6045.123 (Mac) 之前的版本
  • Google Chrome 119.0.6045.123/.124 (Windows) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 119.0.6045.123 (Linux) 或之後版本
  • 更新至 119.0.6045.123 (Mac) 或之後版本
  • 更新至 119.0.6045.123/.124 (Windows) 或之後版本

漏洞識別碼


資料來源


相關連結

Google Chrome Remote Code Execution Vulnerability

Release Date: 8 Nov 2023

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

A vulnerability has been identified in Google Chrome. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege and remote code execution on the targeted system.


Impact

  • Remote Code Execution
  • Denial of Service
  • Elevation of Privilege

System / Technologies affected

  • Google Chrome prior to 119.0.6045.123 (Linux)
  • Google Chrome prior to 119.0.6045.123 (Mac)
  • Google Chrome prior to 119.0.6045.123/.124 (Windows)

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 119.0.6045.123 (Linux) or later
  • Update to version 119.0.6045.123 (Mac) or later
  • Update to version 119.0.6045.123/.124 (Windows) or later

Vulnerability Identifier


Source


Related Link

2023年11月7日星期二

三星產品多個漏洞

發佈日期: 2023年11月07日

風險: 極高度風險

類型: 操作系統 - 流動裝置及操作系統

類型: 流動裝置及操作系統

於三星產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發權限提升、遠端執行程式碼、阻斷服務、繞過保安限制、篡改及洩露敏感資料。

 

注意:

有跡象表明 CVE-2023-4863 及 CVE-2023-4211 正在被積極利用。

 

CVE-2023-4863: libwebp 中的堆緩衝區溢位。

CVE-2023-4211:本機非權限使用者可進行不當的 GPU 記憶體處理操作,以取得已釋放的記憶體。


影響

  • 權限提升
  • 資料洩露
  • 遠端執行程式碼
  • 繞過保安限制
  • 阻斷服務
  • 篡改

受影響之系統或技術

  • Android 11, 12, 13

 

有關受影響產品,請參閱以下連結:

https://security.samsungmobile.com/securityUpdate.smsb


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。


漏洞識別碼


資料來源


相關連結

Samsung Products Multiple Vulnerabilities

Release Date: 7 Nov 2023

RISK: Extremely High Risk

TYPE: Operating Systems - Mobile & Apps

TYPE: Mobile & Apps

Multiple vulnerabilities were identified in Samsung Products. A remote attacker could exploit some of these vulnerabilities to trigger  elevation of privilege, remote code execution, denial of service, security restriction bypass, data manipulation and sensitive information disclosure on the targeted system.

 

Note:

There are indications that CVE-2023-4863 and CVE-2023-4211 are under active exploitation in the wild.

 

CVE-2023-4863: Heap buffer overflow in libwebp.

CVE-2023-4211: A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory.


Impact

  • Elevation of Privilege
  • Information Disclosure
  • Remote Code Execution
  • Security Restriction Bypass
  • Denial of Service
  • Data Manipulation

System / Technologies affected

  • Android 11, 12, 13

 

For affected products, please refer to the link below:

https://security.samsungmobile.com/securityUpdate.smsb


Solutions

Before installation of the software, please visit the vendor web-site for more details.


Vulnerability Identifier


Source


Related Link

2023年11月6日星期一

Microsoft Edge 多個漏洞

發佈日期: 2023年11月06日

風險: 中度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Microsoft Edge 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼及仿冒。

 

影響

  • 仿冒
  • 遠端執行程式碼

受影響之系統或技術

  • Microsoft Edge 119.0.2151.44 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 119.0.2151.44 或之後版本

漏洞識別碼


資料來源


相關連結

Microsoft Edge Multiple Vulnerabilities

Release Date: 6 Nov 2023

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities were identified in Microsoft Edge. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution and spoofing on the targeted system.


Impact

  • Spoofing
  • Remote Code Execution

System / Technologies affected

  • Microsoft Edge prior to 119.0.2151.44

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 119.0.2151.44 or later

Vulnerability Identifier


Source


Related Link

Apache Tomcat 多個漏洞

Apache Tomcat 多個漏洞 發佈日期: 2026年08月05日 風險: 中度風險 類型: 伺服器 - 網站伺服器 於 Apache T...