2025年1月15日星期三

Microsoft Monthly Security Update (January 2025)

Microsoft Monthly Security Update (January 2025)

Release Date: 15 Jan 2025

RISK: High Risk

TYPE: Operating Systems - Windows OS

Microsoft has released monthly security update for their products:

 

Vulnerable ProductRisk LevelImpactsNotes
Developer ToolsMedium Risk Medium RiskInformation Disclosure
Remote Code Execution
Elevation of Privilege
 
WindowsHigh Risk High RiskRemote Code Execution
Information Disclosure
Elevation of Privilege
Denial of Service
Security Restriction Bypass
Spoofing
CVE-2025-21333CVE-2025-21334 and CVE-2025-21335 are being exploited in the wild. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Extended Security Updates (ESU)Medium Risk Medium RiskRemote Code Execution
Information Disclosure
Elevation of Privilege
Denial of Service
Security Restriction Bypass
Spoofing
 
Microsoft OfficeMedium Risk Medium RiskRemote Code Execution
Security Restriction Bypass
Spoofing
Elevation of Privilege
Information Disclosure
 
AzureMedium Risk Medium RiskInformation Disclosure 
Microsoft DynamicsMedium Risk Medium RiskRemote Code Execution 

 

Number of 'Extremely High Risk' product(s): 0

Number of 'High Risk' product(s): 1

Number of 'Medium Risk' product(s): 5

Number of 'Low Risk' product(s): 0

Evaluation of overall 'Risk Level': High Risk


Impact

  • Elevation of Privilege
  • Security Restriction Bypass
  • Spoofing
  • Information Disclosure
  • Remote Code Execution
  • Denial of Service

System / Technologies affected

  • Developer Tools
  • Windows
  • Extended Security Updates (ESU)
  • Microsoft Office
  • Azure
  • Microsoft Dynamics

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  •  Apply fixes issued by the vendor.

Vulnerability Identifier


Source


Related Link

Aruba 遠端執行程式碼漏洞

發佈日期: 2025年01月15日

風險: 中度風險

類型: 保安軟件及應用設備 - 保安軟件及應用設備

於 Aruba 發現一個漏洞。遠端攻擊者可利用此漏洞,於目標系統觸發遠端執行任意程式碼。


影響

  • 遠端執行程式碼

受影響之系統或技術

  • AOS-10.4.x.x: 10.4.1.4 及之前版本
  • AOS-8.12.x.x: 8.12.0.2 及之前版本
  • AOS-8.10.x.x: 8.10.0.14 及之前版本

以下已停止維護 (EoM) 的軟件版本受這些漏洞影響,但不適用於此解決方案:

 

  • AOS-10.6.x.x: 所有版本
  • AOS-10.5.x.x: 所有版本
  • AOS-10.3.x.x: 所有版本
  • AOS-8.11.x.x: 所有版本
  • AOS-8.9.x.x: 所有版本
  • AOS-8.8.x.x: 所有版本
  • AOS-8.7.x.x: 所有版本
  • AOS-8.6.x.x: 所有版本
  • AOS-6.5.4.x: 所有版本
  • SD-WAN 8.7.0.0-2.3.0.x: 所有版本
  • SD-WAN 8.6.0.4-2.2.x.x: 所有版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Aruba Remote Code Execution Vulnerability

Release Date: 15 Jan 2025

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

A vulnerability was identified in Aruba. A remote attacker could exploit this vulnerability to trigger remote code execution on the targeted system.


Impact

  • Remote Code Execution

System / Technologies affected

  • AOS-10.4.x.x: 10.4.1.4 and below
  • AOS-8.12.x.x: 8.12.0.2 and below
  • AOS-8.10.x.x: 8.10.0.14 and below

The following software versions that are End of Maintenance (EoM) are affected by these vulnerabilities and are not addressed by this advisory:

 

  • AOS-10.6.x.x: all
  • AOS-10.5.x.x: all
  • AOS-10.3.x.x: all
  • AOS-8.11.x.x: all
  • AOS-8.9.x.x: all
  • AOS-8.8.x.x: all
  • AOS-8.7.x.x: all
  • AOS-8.6.x.x: all
  • AOS-6.5.4.x: all
  • SD-WAN 8.7.0.0-2.3.0.x: all
  • SD-WAN 8.6.0.4-2.2.x.x: all

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Fortinet 產品多個漏洞

發佈日期: 2025年01月15日

風險: 高度風險

類型: 操作系統 - Network

於 Fortinet 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼、洩露敏感資料、繞過保安限制、阻斷服務、篡改及仿冒。

 

注意:

CVE-2024-55591 正被廣泛利用。成功利用漏洞可讓遠端攻擊者透過向 Node.js websocket 模組提出惡意請求,取得超級管理員權限。


影響

  • 遠端執行程式碼
  • 資料洩露
  • 繞過保安限制
  • 篡改
  • 仿冒
  • 阻斷服務

受影響之系統或技術

FortiAnalyzer

  • FortiAnalyzer 6.0 所有版本
  • FortiAnalyzer 6.2 所有版本
  • FortiAnalyzer 6.4 所有版本
  • FortiAnalyzer 7.0 所有版本
  • FortiAnalyzer 7.2.0 至 7.2.5
  • FortiAnalyzer 7.4.0 至 7.4.3
  • FortiAnalyzer 7.6.0 至 7.6.1
  • FortiAnalyzer Cloud 7.4.1 至 7.4.3

FortiAP

  • FortiAP 6.4 所有版本
  • FortiAP 7.0 所有版本
  • FortiAP 7.2.0 至 7.2.3
  • FortiAP 7.4.0 至 7.4.2
  • FortiAP-S 6.2 所有版本
  • FortiAP-S 6.4.0 至 6.4.9
  • FortiAP-W2 6.4 所有版本
  • FortiAP-W2 7.0 所有版本
  • FortiAP-W2 7.2.0 至 7.2.3
  • FortiAP-W2 7.4.0 至 7.4.2

FortiManager

  • FortiManager 6.0 所有版本
  • FortiManager 6.2 所有版本
  • FortiManager 6.4 所有版本
  • FortiManager 7.0 所有版本
  • FortiManager 7.2.0 至 7.2.8
  • FortiManager 7.4.0 至 7.4.5
  • FortiManager 7.6.0 至 7.6.1
  • FortiManager Cloud 7.0.1 至 7.0.12
  • FortiManager Cloud 7.2.1 至 7.2.7
  • FortiManager Cloud 7.4.0 至 7.4.4
  • FortiManager Cloud 7.6.0 至 7.6.1

FortiOS

  • FortiOS 6.2 所有版本
  • FortiOS 6.4 所有版本
  • FortiOS 7.0 所有版本
  • FortiOS 7.2 所有版本
  • FortiOS 7.4.0 至 7.4.4
  • FortiOS 7.6.0

FortiProxy

  • FortiProxy 1.0 所有版本
  • FortiProxy 1.1 所有版本
  • FortiProxy 1.2 所有版本
  • FortiProxy 2.0 所有版本
  • FortiProxy 7.0.0 至 7.0.19
  • FortiProxy 7.2.0 至 7.2.12
  • FortiProxy 7.4.0 至 7.4.5

FortiClientWindows

  • FortiClientWindows 6.4 所有版本
  • FortiClientWindows 7.0 所有版本
  • FortiClientWindows 7.2 所有版本
  • FortiClientWindows 7.4.0

FortiClientEMS

  • FortiClientEMS 6.2 所有版本
  • FortiClientEMS 6.4 所有版本
  • FortiClientEMS 7.0.0 至 7.0.10
  • FortiClientEMS 7.2.0 至 7.2.3

FortiWeb

  • FortiWeb 6.4 所有版本
  • FortiWeb 7.0 所有版本
  • FortiWeb 7.2 所有版本
  • FortiWeb 7.4.0 至 7.4.4
  • FortiWeb 7.6.0

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Fortinet Products Multiple Vulnerabilities

Release Date: 15 Jan 2025

RISK: High Risk

TYPE: Operating Systems - Networks OS

Multiple vulnerabilities were identified in Fortinet Products. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution, sensitive information disclosure, security restriction bypass, data manipulation, denial of service and spoofing on the targeted system.

 

Note: 

CVE-2024-55591 is being exploited in the wild. Successful exploitation allows remote attackers to gain super-admin privileges by making malicious requests to the Node.js websocket module.

 


Impact

  • Remote Code Execution
  • Information Disclosure
  • Security Restriction Bypass
  • Data Manipulation
  • Spoofing
  • Denial of Service

System / Technologies affected

FortiAnalyzer

  • FortiAnalyzer 6.0 all versions
  • FortiAnalyzer 6.2 all versions
  • FortiAnalyzer 6.4 all versions
  • FortiAnalyzer 7.0 all versions
  • FortiAnalyzer 7.2.0 through 7.2.5
  • FortiAnalyzer 7.4.0 through 7.4.3
  • FortiAnalyzer 7.6.0 through 7.6.1
  • FortiAnalyzer Cloud 7.4.1 through 7.4.3

FortiAP

  • FortiAP 6.4 all versions
  • FortiAP 7.0 all versions
  • FortiAP 7.2.0 through 7.2.3
  • FortiAP 7.4.0 through 7.4.2
  • FortiAP-S 6.2 all versions
  • FortiAP-S 6.4.0 through 6.4.9
  • FortiAP-W2 6.4 all versions
  • FortiAP-W2 7.0 all versions
  • FortiAP-W2 7.2.0 through 7.2.3
  • FortiAP-W2 7.4.0 through 7.4.2

FortiManager

  • FortiManager 6.0 all versions
  • FortiManager 6.2 all versions
  • FortiManager 6.4 all versions
  • FortiManager 7.0 all versions
  • FortiManager 7.2.0 through 7.2.8
  • FortiManager 7.4.0 through 7.4.5
  • FortiManager 7.6.0 through 7.6.1
  • FortiManager Cloud 7.0.1 through 7.0.12
  • FortiManager Cloud 7.2.1 through 7.2.7
  • FortiManager Cloud 7.4.0 through 7.4.4
  • FortiManager Cloud 7.6.0 through 7.6.1

FortiOS

  • FortiOS 6.2 all versions
  • FortiOS 6.4 all versions
  • FortiOS 7.0 all versions
  • FortiOS 7.2 all versions
  • FortiOS 7.4.0 through 7.4.4
  • FortiOS 7.6.0

FortiProxy

  • FortiProxy 1.0 all versions
  • FortiProxy 1.1 all versions
  • FortiProxy 1.2 all versions
  • FortiProxy 2.0 all versions
  • FortiProxy 7.0.0 through 7.0.19
  • FortiProxy 7.2.0 through 7.2.12
  • FortiProxy 7.4.0 through 7.4.5

FortiClientWindows

  • FortiClientWindows 6.4 all versions
  • FortiClientWindows 7.0 all versions
  • FortiClientWindows 7.2 all versions
  • FortiClientWindows 7.4.0

FortiClientEMS

  • FortiClientEMS 6.2 all versions
  • FortiClientEMS 6.4 all versions
  • FortiClientEMS 7.0.0 through 7.0.10
  • FortiClientEMS 7.2.0 through 7.2.3

FortiWeb

  • FortiWeb 6.4 all versions
  • FortiWeb 7.0 all versions
  • FortiWeb 7.2 all versions
  • FortiWeb 7.4.0 through 7.4.4
  • FortiWeb 7.6.0

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Google Chrome 多個漏洞

發佈日期: 2025年01月15日

風險: 中度風險

類型: 用戶端 - 瀏覽器

於 Google Chrome 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼、阻斷服務狀況、繞過保安限制及敏感資料洩露。


影響

  • 遠端執行程式碼
  • 阻斷服務
  • 資料洩露
  • 繞過保安限制

受影響之系統或技術

  • Google Chrome 132.0.6834.83 (Linux) 之前的版本
  • Google Chrome 132.0.6834.83/84 (Mac) 之前的版本
  • Google Chrome 132.0.6834.83/84 (Windows) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 升級 132.0.6834.83 (Linux) 或之後的版本
  • 升級 132.0.6834.83/84 (Mac) 或之後的版本
  • 升級 132.0.6834.83/84 (Windows) 或之後的版本

漏洞識別碼


資料來源


相關連結

Google Chrome Multiple Vulnerabilities

Release Date: 15 Jan 2025

RISK: Medium Risk

TYPE: Clients - Browsers

Multiple vulnerabilities were identified in Google Chrome. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution, denial of service condition, security restriction bypass and sensitive information disclosure on the targeted system.


Impact

  • Remote Code Execution
  • Denial of Service
  • Information Disclosure
  • Security Restriction Bypass

System / Technologies affected

  • Google Chrome prior to 132.0.6834.83 (Linux)
  • Google Chrome prior to 132.0.6834.83/84 (Mac)
  • Google Chrome prior to 132.0.6834.83/84 (Windows)

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 132.0.6834.83 (Linux) or later
  • Update to version 132.0.6834.83/84 (Mac) or later
  • Update to version 132.0.6834.83/84 (Windows) or later

Vulnerability Identifier


Source


Related Link

2025年1月14日星期二

Veeam Backup & Replication 資料洩露漏洞

發佈日期: 2025年01月14日

風險: 中度風險

類型: 伺服器 - 網站伺服器

於 Veeam Backup & Replication 發現一個漏洞。遠端攻擊者可利用此漏洞,於目標系統觸發洩露敏感資料及繞過保安限制。


影響

  • 資料洩露
  • 繞過保安限制

受影響之系統或技術

  • Veeam Backup for Microsoft Azure 7.1.0.22 及之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Veeam Backup & Replication Information Disclosure Vulnerability

Release Date: 14 Jan 2025

RISK: Medium Risk

TYPE: Servers - Web Servers

A vulnerability was identified in Veeam Backup & Replication.  A remote attacker could exploit this vulnerability to trigger sensitive information disclosure and security restriction bypass on the targeted system.


Impact

  • Information Disclosure
  • Security Restriction Bypass

System / Technologies affected

  • Veeam Backup for Microsoft Azure 7.1.0.22 and all earlier versions

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

2025年1月13日星期一

SUSE Linux 內核多個漏洞

發佈日期: 2025年01月13日

風險: 中度風險

類型: 操作系統 - LINUX

於 SUSE Linux 內核發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、遠端執行任意程式碼、洩露敏感資料及繞過保安限制。


影響

  • 遠端執行程式碼
  • 阻斷服務
  • 資料洩露
  • 繞過保安限制
  • 權限提升

受影響之系統或技術

  • SUSE Linux Enterprise High Performance Computing 12 SP5
  • SUSE Linux Enterprise Server 12 SP5
  • SUSE Linux Enterprise Server 12 SP5 LTSS
  • SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security
  • SUSE Linux Enterprise Server for SAP Applications 12 SP5

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

SUSE Linux Kernel Multiple Vulnerabilities

Release Date: 13 Jan 2025

RISK: Medium Risk

TYPE: Operating Systems - Linux

Multiple vulnerabilities were identified in SUSE Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, remote code execution, sensitive information disclosure and security restriction bypass on the targeted system.

 


Impact

  • Remote Code Execution
  • Denial of Service
  • Information Disclosure
  • Security Restriction Bypass
  • Elevation of Privilege

System / Technologies affected

  • SUSE Linux Enterprise High Performance Computing 12 SP5
  • SUSE Linux Enterprise Server 12 SP5
  • SUSE Linux Enterprise Server 12 SP5 LTSS
  • SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security
  • SUSE Linux Enterprise Server for SAP Applications 12 SP5

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

蘋果 macOS 繞過保安限制漏洞

蘋果 macOS 繞過保安限制漏洞 發佈日期: 2026年08月07日 於蘋果 macOS 發現一個漏洞。遠端攻擊者可利用此漏洞,於目標系統觸發繞過保安限制。 影響 繞過保安限制 受影響之系統或技術 macOS Sequoia 15.7.9 以前的版本 macOS Sonoma ...