2024年2月14日星期三

QNAP NAS 執行任意程式碼漏洞

發佈日期: 2024年02月14日

風險: 中度風險

類型: 伺服器 - 其他伺服器

類型: 其他伺服器

於 QNAP NAS 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼。


影響

  • 遠端執行程式碼

受影響之系統或技術

  • QTS 5.1.0.2444 build 20230629 之前版本
  • QTS 5.0.1.2145 build 20220903 之前版本
  • QTS 5.0.0.1986 build 20220324 之前版本
  • QTS 4.5.4.2012 build 20220419 之前版本
  • QTS 4.3.6.2665 build 20240131 之前版本
  • QTS 4.3.4.2675 build 20240131 之前版本
  • QTS 4.3.3.2644 build 20240131 之前版本
  • QTS 4.2.6 build 20240131 之前版本
  • QuTS hero h5.1.0.2466 build 20230721 之前版本
  • QuTS hero h5.0.1.2192 build 20221020 之前版本
  • QuTS hero h5.0.0.1986 build 20220324 之前版本
  • QuTS hero h4.5.4.1991 build 20220330 之前版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

QNAP NAS Remote Code Execution Vulnerabilities

Release Date: 14 Feb 2024

RISK: Medium Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

Multiple vulnerabilities were identified in QNAP NAS. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution on the targeted system.


Impact

  • Remote Code Execution

System / Technologies affected

  • QTS version prior to 5.1.0.2444 build 20230629
  • QTS version prior to 5.0.1.2145 build 20220903
  • QTS version prior to 5.0.0.1986 build 20220324
  • QTS version prior to 4.5.4.2012 build 20220419
  • QTS version prior to 4.3.6.2665 build 20240131
  • QTS version prior to 4.3.4.2675 build 20240131
  • QTS version prior to 4.3.3.2644 build 20240131
  • QTS version prior to 4.2.6 build 20240131
  • QuTS hero version prior to h5.1.0.2466 build 20230721
  • QuTS hero version prior to h5.0.1.2192 build 20221020
  • QuTS hero version prior to h5.0.0.1986 build 20220324
  • QuTS hero version prior to h4.5.4.1991 build 20220330

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Adobe 每月保安更新 (2024年2月)

發佈日期: 2024年02月14日

風險: 中度風險

類型: 用戶端 - 辦公室應用

類型: 辦公室應用

Adobe已為產品提供本月保安更新:

 

受影響產品風險程度影響備註詳情(包括 CVE)
Magento and Adobe Commerce中度風險 中度風險跨網站指令碼
遠端執行程式碼
阻斷服務
繞過保安限制
 APSB24-03
Adobe Substance 3D Painter中度風險 中度風險遠端執行程式碼
資料洩露
阻斷服務
 APSB24-04
Adobe Acrobat and Reader中度風險 中度風險遠端執行程式碼
阻斷服務
資料洩露
 APSB24-07
Adobe Framemaker中度風險 中度風險繞過保安限制 APSB24-10
Adobe Audition中度風險 中度風險遠端執行程式碼 APSB24-11
Adobe Substance 3D Designer中度風險 中度風險遠端執行程式碼 APSB24-13

 

「極高度風險」產品數目:0

「高度風險」產品數目:0

「中度風險」產品數目:6

「低度風險」產品數目:0

整體「風險程度」評估:中度風險


影響

  • 遠端執行程式碼
  • 資料洩露
  • 跨網站指令碼
  • 阻斷服務
  • 繞過保安限制

受影響之系統或技術

  • Adobe Commerce 2.4.6-p3 及以前版本
  • Adobe Commerce 2.4.5-p5 及以前版本
  • Adobe Commerce 2.4.4-p6 及以前版本
  • Adobe Commerce 2.4.3-ext-5 及以前版本*
  • Adobe Commerce 2.4.2-ext-5 及以前版本*
  • Adobe Commerce 2.4.1-ext-5 及以前版本*
  • Adobe Commerce 2.4.0-ext-5 及以前版本*
  • Adobe Commerce 2.3.7-p4-ext-5 及以前版本*
  • Magento Open Source 2.4.6-p3 及以前版本
  • Magento Open Source 2.4.5-p5 及以前版本
  • Magento Open Source 2.4.4-p6 及以前版本
  • Adobe Substance 3D Painter 9.1.1 及以前版本
  • Acrobat DC 23.008.20470 及以前版本
  • Acrobat Reader DC 23.008.20470 及以前版本
  • Acrobat 2020 20.005.30539 及以前版本
  • Acrobat Reader 2020 20.005.30539 及以前版本
  • Adobe FrameMaker Publishing Server Version 2022 Update 1   及以前版本
  • Adobe Audition 24.0.3 及以前版本
  • Adobe Audition 23.6.2 及以前版本
  • Adobe Substance 3D Designer 13.1.0 及以前版本

注意:

* 這些版本僅適用於參與擴展支援計劃的客戶


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

  • 安裝供應商提供的修補程式。個別產品詳情可參考上表「詳情」一欄或執行軟件更新。

漏洞識別碼


資料來源


相關連結

Adobe Monthly Security Update (February 2024)

Release Date: 14 Feb 2024

RISK: Medium Risk

TYPE: Clients - Productivity Products

TYPE: Productivity Products

Adobe has released monthly security update for their products:

 

Vulnerable ProductRisk LevelImpactsNotesDetails (including CVE)
Magento and Adobe CommerceMedium Risk Medium RiskCross-site Scripting
Remote Code Execution
Denial of Service
Security Restriction Bypass
 APSB24-03
Adobe Substance 3D PainterMedium Risk Medium RiskRemote Code Execution
Information Disclosure
Denial of Service
 APSB24-04
Adobe Acrobat and ReaderMedium Risk Medium RiskRemote Code Execution
Denial of Service
Information Disclosure
 APSB24-07
Adobe FramemakerMedium Risk Medium RiskSecurity Restriction Bypass APSB24-10
Adobe AuditionMedium Risk Medium RiskRemote Code Execution APSB24-11
Adobe Substance 3D DesignerMedium Risk Medium RiskRemote Code Execution APSB24-13

 

Number of 'Extremely High Risk' product(s): 0

Number of 'High Risk' product(s): 0

Number of 'Medium Risk' product(s): 6

Number of 'Low Risk' product(s): 0

Evaluation of overall 'Risk Level': Medium Risk


Impact

  • Remote Code Execution
  • Information Disclosure
  • Cross-Site Scripting
  • Denial of Service
  • Security Restriction Bypass

System / Technologies affected

  • Adobe Commerce 2.4.6-p3 and earlier versions
  • Adobe Commerce 2.4.5-p5 and earlier versions
  • Adobe Commerce 2.4.4-p6 and earlier versions
  • Adobe Commerce 2.4.3-ext-5 and earlier* versions
  • Adobe Commerce 2.4.2-ext-5 and earlier* versions
  • Adobe Commerce 2.4.1-ext-5 and earlier* versions
  • Adobe Commerce 2.4.0-ext-5 and earlier* versions
  • Adobe Commerce 2.3.7-p4-ext-5 and earlier* versions
  • Magento Open Source 2.4.6-p3 and earlier versions
  • Magento Open Source 2.4.5-p5 and earlier versions
  • Magento Open Source 2.4.4-p6 and earlier versions
  • Adobe Substance 3D Painter 9.1.1 and earlier versions
  • Acrobat DC 23.008.20470 and earlier versions
  • Acrobat Reader DC 23.008.20470 and earlier versions
  • Acrobat 2020 20.005.30539 and earlier versions
  • Acrobat Reader 2020 20.005.30539 and earlier versions
  • Adobe FrameMaker Publishing Server Version 2022 Update 1   and earlier versions
  • Adobe Audition 24.0.3 and earlier versions
  • Adobe Audition 23.6.2 and earlier versions
  • Adobe Substance 3D Designer 13.1.0 and earlier versions

Note:

* These versions are only applicable to customers participating in the Extended Support Program


Solutions

Before installation of the software, please visit the vendor web-site for more details.

  • Apply fixes issued by the vendor. Please refer to 'Details' column in the above table for details of individual product update or run software update

Vulnerability Identifier


Source


Related Link

微軟每月保安更新 (2024年2月)

發佈日期: 2024年02月14日

風險: 中度風險

類型: 操作系統 - 視窗操作系統

類型: 視窗操作系統

微軟已為產品提供本月保安更新:

 

受影響產品風險程度影響備註
瀏覽器中度風險 中度風險遠端執行程式碼 
Azure中度風險 中度風險遠端執行程式碼
權限提升
仿冒
 
開發者工具中度風險 中度風險遠端執行程式碼
阻斷服務
 
視窗中度風險 中度風險阻斷服務
權限提升
資料洩露
遠端執行程式碼
繞過保安限制
仿冒

CVE-2024-21351  正被廣泛利用。該漏洞能夠將代碼注入SmartScreen,從而潛在地獲得執行代碼權限,這可能導致一些數據洩露、系統不可用或者兩者兼而有之。

 

CVE-2024-21412  正被廣泛利用。該漏洞可能繞過 Windows 中的 MoTW 警告。

延伸安全性更新 (ESU)中度風險 中度風險阻斷服務
資料洩露
遠端執行程式碼
權限提升
仿冒
 
微軟 Dynamics中度風險 中度風險仿冒
資料洩露
 
微軟 Office中度風險 中度風險遠端執行程式碼
權限提升
資料洩露
 
System Center中度風險 中度風險權限提升 
Exchange Server中度風險 中度風險權限提升 
Mariner低度風險 低度風險  

 

「極高度風險」產品數目:0

「高度風險」產品數目:0

「中度風險」產品數目:9

「低度風險」產品數目:1

整體「風險程度」評估:中度風險


影響

  • 遠端執行程式碼
  • 繞過保安限制
  • 權限提升
  • 阻斷服務
  • 資料洩露
  • 仿冒

受影響之系統或技術

  • 瀏覽器
  • Azure
  • 開發者工具
  • 視窗
  • 延伸安全性更新 (ESU)
  • 微軟 Dynamics
  • 微軟 Office
  • System Center
  • Exchange Server
  • Mariner

解決方案

在安裝軟體之前,請先瀏覽軟體供應商之網站,以獲得更多詳細資料。

  • 安裝軟件供應商提供的修補程式。
 

漏洞識別碼

 

資料來源


相關連結

Microsoft Monthly Security Update (February 2024)

Release Date: 14 Feb 2024

RISK: Medium Risk

TYPE: Operating Systems - Windows OS

TYPE: Windows OS

Microsoft has released monthly security update for their products:

 

Vulnerable ProductRisk LevelImpactsNotes
BrowserMedium Risk Medium RiskRemote Code Execution 
AzureMedium Risk Medium RiskRemote Code Execution
Elevation of Privilege
Spoofing
 
Developer ToolsMedium Risk Medium RiskRemote Code Execution
Denial of Service
 
WindowsMedium Risk Medium RiskDenial of Service
Elevation of Privilege
Information Disclosure
Remote Code Execution
Security Restriction Bypass
Spoofing

CVE-2024-21351  is being exploited in the wild. The vulnerability allows a malicious actor to inject code into SmartScreen and potentially gain code execution, which could potentially lead to some data exposure, lack of system availability, or both.

 

CVE-2024-21412  is being exploited in the wild.  The vulnerability could bypass Mark of the Web (MoTW) warnings in Windows.

Extended Security Updates (ESU)Medium Risk Medium RiskDenial of Service
Information Disclosure
Remote Code Execution
Elevation of Privilege
Spoofing
 
Microsoft DynamicsMedium Risk Medium RiskSpoofing
Information Disclosure
 
Microsoft OfficeMedium Risk Medium RiskRemote Code Execution
Elevation of Privilege
Information Disclosure
 
System CenterMedium Risk Medium RiskElevation of Privilege 
Exchange ServerMedium Risk Medium RiskElevation of Privilege 
MarinerLow Risk Low Risk  

 

Number of 'Extremely High Risk' product(s): 0

Number of 'High Risk' product(s): 0

Number of 'Medium Risk' product(s): 9

Number of 'Low Risk' product(s): 1

Evaluation of overall 'Risk Level': Medium Risk


Impact

  • Remote Code Execution
  • Security Restriction Bypass
  • Elevation of Privilege
  • Denial of Service
  • Information Disclosure
  • Spoofing

System / Technologies affected

  • Browser
  • Azure
  • Developer Tools
  • Windows
  • Extended Security Updates (ESU)
  • Microsoft Dynamics
  • Microsoft Office
  • System Center
  • Exchange Server
  • Mariner

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  •  Apply fixes issued by the vendor.

Vulnerability Identifier

 

Source


Related Link

Zoom 產品多個漏洞

發佈日期: 2024年02月14日

風險: 中度風險

類型: 用戶端 - 辦公室應用

類型: 辦公室應用

於 Zoom 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升及洩露敏感資料。


影響

  • 阻斷服務
  • 權限提升
  • 資料洩露

受影響之系統或技術

  • Zoom Desktop Client for Linux 5.16.5 之前的版本
  • Zoom Desktop Client for Linux 5.17.0 之前的版本
  • Zoom Desktop Client for Windows 5.16.5 之前的版本
  • Zoom Desktop Client for Windows 5.17.0 之前的版本
  • Zoom Desktop Client for macOS 5.16.5 之前的版本
  • Zoom Desktop Client for macOS 5.17.0 之前的版本
  • Zoom Meeting SDK for Windows 5.16.5 之前的版本
  • Zoom Meeting SDK for Windows 5.17.0 之前的版本
  • Zoom Meeting SDKs 5.16.5 之前的版本
  • Zoom Meeting SDKs 5.17.0 之前的版本
  • Zoom Mobile App for Android 5.16.5 之前的版本
  • Zoom Mobile App for Android 5.17.0 之前的版本
  • Zoom Mobile App for iOS 5.16.5 之前的版本
  • Zoom Mobile App for iOS 5.17.0 之前的版本
  • Zoom Rooms Client for Windows 5.17.0 之前的版本
  • Zoom Rooms Clients 5.17.0 之前的版本
  • Zoom VDI Client for Windows 5.16.10 (除了 5.14.14 and 5.15.12) 之前的版本
  • Zoom VDI Client for Windows 5.17.5 (除了 5.15.15 and 5.16.10) 之前的版本
  • Zoom VDI Client for Windows 5.17.5 (除了 5.15.15 and 5.16.12) 之前的版本
  • Zoom Video SDK for Windows 5.16.5 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Zoom Products Multiple Vulnerabilities

Release Date: 14 Feb 2024

RISK: Medium Risk

TYPE: Clients - Productivity Products

TYPE: Productivity Products

Multiple vulnerabilities have been identified in Zoom products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege and sensitive information disclosure on the targeted system.


Impact

  • Denial of Service
  • Elevation of Privilege
  • Information Disclosure

System / Technologies affected

  • Zoom Desktop Client for Linux before version 5.16.5
  • Zoom Desktop Client for Linux before version 5.17.0
  • Zoom Desktop Client for Windows before version 5.16.5
  • Zoom Desktop Client for Windows before version 5.17.0
  • Zoom Desktop Client for macOS before version 5.16.5
  • Zoom Desktop Client for macOS before version 5.17.0
  • Zoom Meeting SDK for Windows before version 5.16.5
  • Zoom Meeting SDK for Windows before version 5.17.0
  • Zoom Meeting SDKs before version 5.16.5
  • Zoom Meeting SDKs before version 5.17.0
  • Zoom Mobile App for Android before version 5.16.5
  • Zoom Mobile App for Android before version 5.17.0
  • Zoom Mobile App for iOS before version 5.16.5
  • Zoom Mobile App for iOS before version 5.17.0
  • Zoom Rooms Client for Windows before version 5.17.0
  • Zoom Rooms Clients before version 5.17.0
  • Zoom VDI Client for Windows before version 5.16.10 (excluding 5.14.14 and 5.15.12)
  • Zoom VDI Client for Windows before version 5.17.5 (excluding 5.15.15 and 5.16.10)
  • Zoom VDI Client for Windows before version 5.17.5 (excluding 5.15.15 and 5.16.12)
  • Zoom Video SDK for Windows before version 5.16.5

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

2024年2月10日星期六

Fortinet 產品多個漏洞

發佈日期: 2024年02月09日

風險: 中度風險

類型: 操作系統 - Network

類型: Network

於 Fortinet 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行任意程式碼、洩露敏感資料及跨網站指令碼。


影響

  • 阻斷服務
  • 遠端執行程式碼
  • 資料洩露
  • 跨網站指令碼

受影響之系統或技術

  • FortiProxy 7.4 版本 7.4.0 至 7.4.1
  • FortiProxy 7.2 版本 7.2.0 至 7.2.7
  • FortiProxy 7.0 所有版本
  • FortiOS 7.4 版本 7.4.0 至 7.4.2
  • FortiOS 7.2 版本 7.2.0 至 7.2.6
  • FortiOS 7.0 所有版本
  • FortiOS 6.4 版本 6.4.0 至 6.4.14
  • FortiOS 6.2 版本 6.2.0 至 6.2.15
  • FortiOS 6.0 所有版本
  • FortiNAC 9.4 版本 9.4.0 至 9.4.3
  • FortiNAC 9.2 所有版本
  • FortiNAC 9.1 所有版本
  • FortiNAC 8.8 所有版本
  • FortiNAC 8.7 所有版本
  • FortiNAC 8.6 所有版本
  • FortiNAC 8.5 所有版本
  • FortiNAC 8.3 所有版本
  • FortiNAC 7.2 版本 7.2.0 至 7.2.2
  • FortiClientEMS 7.2 版本 7.2.0 至 7.2.2
  • FortiClientEMS 7.0 版本 7.0.6 至 7.0.10
  • FortiClientEMS 7.0 版本 7.0.0 至 7.0.4
  • FortiClientEMS 6.4 所有版本
  • FortiClientEMS 6.2 所有版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Fortinet Products Multiple Vulnerabilities

Release Date: 9 Feb 2024

RISK: Medium Risk

TYPE: Operating Systems - Networks OS

TYPE: Networks OS

Multiple vulnerabilities were identified in Fortinet Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution, sensitive information disclosure and cross-site scripting on the targeted system.


Impact

  • Denial of Service
  • Remote Code Execution
  • Information Disclosure
  • Cross-Site Scripting

System / Technologies affected

  • FortiProxy 7.4 version 7.4.0 through 7.4.1
  • FortiProxy 7.2 version 7.2.0 through 7.2.7
  • FortiProxy 7.0 all versions
  • FortiOS 7.4 version 7.4.0 through 7.4.2
  • FortiOS 7.2 version 7.2.0 through 7.2.6
  • FortiOS 7.0 all versions
  • FortiOS 6.4 version 6.4.0 through 6.4.14
  • FortiOS 6.2 version 6.2.0 through 6.2.15
  • FortiOS 6.0 all versions
  • FortiNAC 9.4 version 9.4.0 through 9.4.3
  • FortiNAC 9.2 all versions
  • FortiNAC 9.1 all versions
  • FortiNAC 8.8 all versions
  • FortiNAC 8.7 all versions
  • FortiNAC 8.6 all versions
  • FortiNAC 8.5 all versions
  • FortiNAC 8.3 all versions
  • FortiNAC 7.2 version 7.2.0 through 7.2.2
  • FortiClientEMS 7.2 version 7.2.0 through 7.2.2
  • FortiClientEMS 7.0 version 7.0.6 through 7.0.10
  • FortiClientEMS 7.0 version 7.0.0 through 7.0.4
  • FortiClientEMS 6.4 all versions
  • FortiClientEMS 6.2 all versions

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Ivanti 產品繞過保安限制漏洞

發佈日期: 2024年02月09日

風險: 中度風險

類型: 操作系統 - Network

類型: Network

於 Ivanti 產品發現一個漏洞。遠端攻擊者可利用此漏洞,於目標系統觸發繞過保安限制。


影響

  • 繞過保安限制

受影響之系統或技術

  • Ivanti Connect Secure 版本 9.1R14.4
  • Ivanti Connect Secure 版本 9.1R17.2
  • Ivanti Connect Secure 版本 9.1R18.3
  • Ivanti Connect Secure 版本 22.4R2.2
  • Ivanti Connect Secure 版本 22.5R1.1
  • Ivanti Policy Secure 版本 22.5R1.1
  • ZTA 版本 22.6R1.3

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Ivanti Products Security Restriction Bypass Vulnerability

Release Date: 9 Feb 2024

RISK: Medium Risk

TYPE: Operating Systems - Networks OS

TYPE: Networks OS

A vulnerability has been identified in Ivanti Products. A remote attacker could exploit this vulnerability to trigger security restriction bypass on the targeted system.


Impact

  • Security Restriction Bypass

System / Technologies affected

  • Ivanti Connect Secure version 9.1R14.4
  • Ivanti Connect Secure version 9.1R17.2
  • Ivanti Connect Secure version 9.1R18.3
  • Ivanti Connect Secure version 22.4R2.2
  • Ivanti Connect Secure version 22.5R1.1
  • Ivanti Policy Secure version 22.5R1.1
  • ZTA version 22.6R1.3

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Microsoft Edge 多個漏洞

發佈日期: 2024年02月09日

風險: 中度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Microsoft Edge 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發資料洩露、遠端執行任意程式碼及阻斷服務狀況。


影響

  • 遠端執行程式碼
  • 阻斷服務
  • 資料洩露

受影響之系統或技術

  • Microsoft Edge (Stable) 121.0.2277.113 之前的版本
  • Microsoft Edge (Extended Stable) 120.0.2210.175 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 Microsoft Edge (Stable) 121.0.2277.113 或之後版本
  • 更新至 Microsoft Edge (Extended Stable) 120.0.2210.175 或之後版本

漏洞識別碼


資料來源


相關連結

Microsoft Edge Multiple Vulnerabilities

Release Date: 9 Feb 2024

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities were identified in Microsoft Edge.  A remote attacker could exploit some of these vulnerabilities to trigger information disclosure, remote code execution and denial of service condition on the targeted system.


Impact

  • Remote Code Execution
  • Denial of Service
  • Information Disclosure

System / Technologies affected

  • Microsoft Edge (Stable) prior to 121.0.2277.113
  • Microsoft Edge (Extended Stable) prior to 120.0.2210.175

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to Microsoft Edge (Stable) version 121.0.2277.113 or later
  • Update to Microsoft Edge (Extended Stable) version 120.0.2210.175 or later

Vulnerability Identifier


Source


Related Link

ChromeOS 多個漏洞

發佈日期: 2024年02月08日

風險: 中度風險

類型: 操作系統 - 其他操作系統

類型: 其他操作系統

於 ChromeOS 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行任意程式碼、繞過保安限制及資料篡改。


影響

  • 遠端執行程式碼
  • 阻斷服務
  • 繞過保安限制
  • 篡改

受影響之系統或技術

  • 121.0.6167.159 (平台版本: 15699.58.0) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式,詳情請參閱以下連結:


漏洞識別碼


資料來源


相關連結

ChromeOS Multiple Vulnerabilities

Release Date: 8 Feb 2024

RISK: Medium Risk

TYPE: Operating Systems - Others OS

TYPE: Others OS

Multiple vulnerabilities were identified in ChromeOS. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution, security restriction bypass and data manipulation on the targeted system.


Impact

  • Remote Code Execution
  • Denial of Service
  • Security Restriction Bypass
  • Data Manipulation

System / Technologies affected

  • Version prior to 121.0.6167.159 (Platform Version: 15699.58.0)

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor. For detail, please refer to the link below:


Vulnerability Identifier


Source


Related Link

思科 Unity Connection 遠端執行程式碼漏洞

發佈日期: 2024年02月08日

風險: 中度風險

類型: 保安軟件及應用設備 - 保安軟件及應用設備

類型: 保安軟件及應用設備

於思科 ClamAV 發現一個漏洞。遠端攻擊者可利用這個漏洞,於目標系統觸發阻斷服務狀況。


影響

  • 阻斷服務

受影響之系統或技術

  • 思科 Secure Endpoint Connector for Windows 7.5.17 以前的版本
  • 思科 Secure Endpoint Connector for Windows 8.2.1 以前的版本
  • 思科 Secure Endpoint Private Cloud 3.8.0 以前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Cisco ClamAV Denial of Service Vulnerability

Release Date: 8 Feb 2024

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

A vulnerability was identified in Cisco ClamAV. A remote attacker could exploit this vulnerability to trigger denial of service condition on the targeted system.


Impact

  • Denial of Service

System / Technologies affected

  • Cisco Secure Endpoint Connector for Windows versions prior to 7.5.17
  • Cisco Secure Endpoint Connector for Windows versions prior to 8.2.1
  • Cisco Secure Endpoint Private Cloud versions prior to 3.8.0

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

思科產品多個漏洞

思科產品多個漏洞 於思科產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況,資料篡改及繞過保安限制。 影響 阻斷服務 繞過保安限制 篡改 受影響之系統或技術 Cisco IOS Cisco IOS XE 請參考供應商發佈的連結以了解受影響的版本: https:...