2025年10月15日星期三

Google Chrome 遠端執行程式碼漏洞

Google Chrome 遠端執行程式碼漏洞

發佈日期: 2025年10月15日

風險: 中度風險

類型: 用戶端 - 瀏覽器

於 Google Chrome 發現一個漏洞。遠端攻擊者可利用此漏洞,於目標系統觸發遠端執行任意程式碼。


影響

  • 遠端執行程式碼

受影響之系統或技術

  • Google Chrome 141.0.7390.107 (Linux) 之前的版本
  • Google Chrome 141.0.7390.107/.108 (Mac) 之前的版本
  • Google Chrome 141.0.7390.107/.108 (Windows) 之前的版本
  • Google Chrome 141.0.7390.111 (Android) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 升級 141.0.7390.107 (Linux) 或之後的版本
  • 升級 141.0.7390.107/.108 (Mac) 或之後的版本
  • 升級 141.0.7390.107/.108 (Windows) 或之後的版本
  • 升級 141.0.7390.111 (Android) 或之後的版本

漏洞識別碼


資料來源


相關連結

Google Chrome Remote Code Execution Vulnerability

Google Chrome Remote Code Execution Vulnerability

Release Date: 15 Oct 2025

RISK: Medium Risk

TYPE: Clients - Browsers

A vulnerability was identified in Google Chrome. A remote attacker could exploit this vulnerability to trigger remote code execution on the targeted system.


Impact

  • Remote Code Execution

System / Technologies affected

  • Google Chrome prior to 141.0.7390.107 (Linux)
  • Google Chrome prior to 141.0.7390.107/.108 (Mac)
  • Google Chrome prior to 141.0.7390.107/.108 (Windows)
  • Google Chrome prior to 141.0.7390.111 (Android)

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 141.0.7390.107 (Linux) or later
  • Update to version 141.0.7390.107/.108 (Mac) or later
  • Update to version 141.0.7390.107/.108 (Windows) or later
  • Update to version 141.0.7390.111 (Android) or later

Vulnerability Identifier


Source


Related Link

Mozilla 產品多個漏洞

Mozilla 產品多個漏洞

發佈日期: 2025年10月15日

風險: 中度風險

類型: 用戶端 - 瀏覽器

於 Mozilla 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、資料篡改、繞過保安限制、遠端執行任意程式碼、仿冒及敏感資料洩露。


影響

  • 資料洩露
  • 篡改
  • 繞過保安限制
  • 遠端執行程式碼
  • 仿冒
  • 阻斷服務

受影響之系統或技術

以下版本之前的版本﹕

 

  • Firefox 144
  • Firefox ESR 115.29
  • Firefox ESR 140.4
  • Thunderbird 140.4
  • Thunderbird 144

解決方案

在安裝軟體之前,請先瀏覽供應商之官方網站,以獲得更多詳細資料。

更新至版本:

 

  • Firefox 144
  • Firefox ESR 115.29
  • Firefox ESR 140.4
  • Thunderbird 140.4
  • Thunderbird 144

漏洞識別碼


資料來源


相關連結

Mozilla Products Multiple Vulnerabilities

Mozilla Products Multiple Vulnerabilities

Release Date: 15 Oct 2025

RISK: Medium Risk

TYPE: Clients - Browsers

Multiple vulnerabilities were identified in Mozilla Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, data manipulation, security restriction bypass, remote code execution, spoofing and sensitive information disclosure on the targeted system.


Impact

  • Information Disclosure
  • Data Manipulation
  • Security Restriction Bypass
  • Remote Code Execution
  • Spoofing
  • Denial of Service

System / Technologies affected

Versions prior to:

 

  • Firefox 144
  • Firefox ESR 115.29
  • Firefox ESR 140.4
  • Thunderbird 140.4
  • Thunderbird 144

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 

  • Firefox 144
  • Firefox ESR 115.29
  • Firefox ESR 140.4
  • Thunderbird 140.4
  • Thunderbird 144

Vulnerability Identifier


Source


Related Link

Zoom 產品資料洩露漏洞

Zoom 產品資料洩露漏洞

發佈日期: 2025年10月15日

風險: 中度風險

類型: 用戶端 - 辦公室應用

於 Zoom 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發洩露敏感資料。


影響

  • 資料洩露

受影響之系統或技術

  • Zoom Meeting SDK for Windows 6.5.5 之前的版本
  • Zoom Rooms for Windows 6.5.1 之前的版本
  • Zoom Rooms for macOS 6.5.1 之前的版本
  • Zoom Rooms for Android 6.5.1 之前的版本
  • Zoom Rooms for iOS 6.5.1 之前的版本
  • Zoom Rooms for iPad 6.5.1 之前的版本
  • Zoom Workplace for Windows 6.5.5 之前的版本
  • Zoom Workplace VDI Client for Windows 6.3.15 及 6.4.13 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之官方網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

 


漏洞識別碼


資料來源


相關連結

Zoom Products Information Disclosure Vulnerabilities

Zoom Products Information Disclosure Vulnerabilities

Release Date: 15 Oct 2025

RISK: Medium Risk

TYPE: Clients - Productivity Products

Multiple vulnerabilities were identified in Zoom Products. A remote attacker could exploit these vulnerabilities to trigger sensitive information disclosure on the targeted system.


Impact

  • Information Disclosure

System / Technologies affected

  • Zoom Meeting SDK for Windows before version 6.5.5
  • Zoom Rooms for Windows before version 6.5.1
  • Zoom Rooms for macOS before version 6.5.1
  • Zoom Rooms for Android before version 6.5.1
  • Zoom Rooms for iOS before version 6.5.1
  • Zoom Rooms for iPad before version 6.5.1
  • Zoom Workplace for Windows before version 6.5.5
  • Zoom Workplace VDI Client for Windows before version 6.3.15 and 6.4.13

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 


Vulnerability Identifier


Source


Related Link

Adobe 每月保安更新 (2025年10月)

Adobe 每月保安更新 (2025年10月)

發佈日期: 2025年10月15日

風險: 中度風險

類型: 用戶端 - 辦公室應用

Adobe已為產品提供本月保安更新:

 

受影響產品風險程度影響備註詳情(包括 CVE)
Adobe Connect中度風險 中度風險跨網站指令碼
遠端執行程式碼
繞過保安限制
 APSB25-70
Adobe Commerce中度風險 中度風險繞過保安限制
跨網站指令碼
權限提升
遠端執行程式碼
 APSB25-94
Adobe Creative Cloud Desktop Application中度風險 中度風險篡改 APSB25-95
Adobe Bridge中度風險 中度風險遠端執行程式碼
資料洩露
 APSB25-96
Adobe Animate中度風險 中度風險

遠端執行程式碼

資料洩露

 APSB25-97
Adobe Experience Manager Screens中度風險 中度風險跨網站指令碼
遠端執行程式碼
 APSB25-98
Substance 3D Viewer中度風險 中度風險遠端執行程式碼
阻斷服務
 APSB25-99
Substance 3D Modeler中度風險 中度風險遠端執行程式碼 APSB25-100
Adobe FrameMaker中度風險 中度風險遠端執行程式碼 APSB25-101
Adobe Illustrator中度風險 中度風險遠端執行程式碼 APSB25-102
Adobe Dimension中度風險 中度風險遠端執行程式碼 APSB25-103
Substance 3D Stager中度風險 中度風險遠端執行程式碼 APSB25-104

 

「極高度風險」產品數目:0

「高度風險」產品數目:0

「中度風險」產品數目:12

「低度風險」產品數目:0

整體「風險程度」評估:中度風險


影響

  • 遠端執行程式碼
  • 阻斷服務
  • 篡改
  • 繞過保安限制
  • 資料洩露
  • 權限提升
  • 跨網站指令碼

受影響之系統或技術

  • Adobe Connect 12.9 及以前版本
  • Adobe Commerce 2.4.9-alpha2 及以前版本
  • Adobe Commerce B2B 1.5.3-alpha2 及以前版本
  • Magento Open Source 2.4.9-alpha2 及以前版本
  • Creative Cloud Desktop Application 6.7.0.278 及以前版本
  • Adobe Bridge  14.1.8 (LTS) 及以前版本
  • Adobe Bridge  15.1.1 及以前版本
  • Adobe Animate 2023 23.0.13 及以前版本
  • Adobe Animate 2024 24.0.10 及以前版本
  • Adobe Experience Manager (AEM) Screens AEM 6.5.22 Screens FP11.6
  • Adobe Substance 3D Viewer 0.25.2 及以前版本
  • Adobe Substance 3D Modeler 1.22.3 及以前版本
  • Adobe FrameMaker 2020 Release Update 9 及以前版本
  • Adobe FrameMaker 2022 Release Update 7 及以前版本
  • Illustrator 2025 29.7 及以前版本
  • Illustrator 2024 28.7.9 及以前版本
  • Adobe Dimension 4.1.4 及以前版本
  • Adobe Substance 3D Stager 3.1.4 及以前版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

  • 安裝供應商提供的修補程式。個別產品詳情可參考上表「詳情」一欄或執行軟件更新。

漏洞識別碼


資料來源


相關連結

Adobe Monthly Security Update (October 2025)

Adobe Monthly Security Update (October 2025)

Release Date: 15 Oct 2025

RISK: Medium Risk

TYPE: Clients - Productivity Products

Adobe has released monthly security update for their products:

 

Vulnerable ProductRisk LevelImpactsNotesDetails (including CVE)
Adobe ConnectMedium Risk Medium RiskCross-site Scripting
Remote Code Execution
Security Restriction Bypass
 APSB25-70
Adobe CommerceMedium Risk Medium RiskSecurity Restriction Bypass
Cross-site Scripting
Elevation of Privilege
Remote Code Execution
 APSB25-94
Adobe Creative Cloud Desktop ApplicationMedium Risk Medium RiskData Manipulation APSB25-95
Adobe BridgeMedium Risk Medium RiskRemote Code Execution
Information Disclosure
 APSB25-96
Adobe AnimateMedium Risk Medium Risk

Remote Code Execution

Information Disclosure

 APSB25-97
Adobe Experience Manager ScreensMedium Risk Medium RiskCross-site Scripting
Remote Code Execution
 APSB25-98
Substance 3D ViewerMedium Risk Medium RiskRemote Code Execution
Denial of Service
 APSB25-99
Substance 3D ModelerMedium Risk Medium RiskRemote Code Execution APSB25-100
Adobe FrameMakerMedium Risk Medium RiskRemote Code Execution APSB25-101
Adobe IllustratorMedium Risk Medium RiskRemote Code Execution APSB25-102
Adobe DimensionMedium Risk Medium RiskRemote Code Execution APSB25-103
Substance 3D StagerMedium Risk Medium RiskRemote Code Execution APSB25-104

 

Number of 'Extremely High Risk' product(s): 0

Number of 'High Risk' product(s): 0

Number of 'Medium Risk' product(s): 12

Number of 'Low Risk' product(s): 0

Evaluation of overall 'Risk Level': Medium Risk


Impact

  • Remote Code Execution
  • Denial of Service
  • Data Manipulation
  • Security Restriction Bypass
  • Information Disclosure
  • Elevation of Privilege
  • Cross-Site Scripting

System / Technologies affected

  • Adobe Connect 12.9 and earlier versions
  • Adobe Commerce 2.4.9-alpha2 and earlier versions
  • Adobe Commerce B2B 1.5.3-alpha2 and earlier versions
  • Magento Open Source 2.4.9-alpha2 and earlier versions
  • Creative Cloud Desktop Application 6.7.0.278 and earlier versions
  • Adobe Bridge  14.1.8 (LTS) and earlier versions
  • Adobe Bridge  15.1.1 and earlier versions
  • Adobe Animate 2023 23.0.13 and earlier versions
  • Adobe Animate 2024 24.0.10 and earlier versions
  • Adobe Experience Manager (AEM) Screens AEM 6.5.22 Screens FP11.6
  • Adobe Substance 3D Viewer 0.25.2 and earlier versions
  • Adobe Substance 3D Modeler 1.22.3 and earlier versions
  • Adobe FrameMaker 2020 Release Update 9 and earlier versions
  • Adobe FrameMaker 2022 Release Update 7 and earlier versions
  • Illustrator 2025 29.7 and earlier versions
  • Illustrator 2024 28.7.9 and earlier versions
  • Adobe Dimension 4.1.4 and earlier versions
  • Adobe Substance 3D Stager 3.1.4 and earlier versions

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  • Apply fixes issued by the vendor. Please refer to 'Details' column in the above table for details of individual product update or run software update.

Vulnerability Identifier


Source


Related Link

微軟每月保安更新 (2025年10月)

微軟每月保安更新 (2025年10月)

發佈日期: 2025年10月15日

風險: 中度風險

類型: 操作系統 - 視窗操作系統

微軟已為產品提供本月保安更新:

 

受影響產品風險程度影響備註
Azure中度風險 中度風險權限提升
遠端執行程式碼
仿冒
 
視窗中度風險 中度風險權限提升
資料洩露
繞過保安限制
遠端執行程式碼
仿冒
阻斷服務
篡改

CVE-2025-59230 正被廣泛利用。Windows 遠端存取連線管理員中的存取控制不當,允許授權攻擊者在本機提升權限。

 

CVE-2025-24990 正被廣泛利用。微軟已知支援的 Windows 作業系統原生附帶的第三方 Agere Modem 驅動程式中存在漏洞。這是關於即將刪除 ltmdm64.sys 驅動程式的公告。該驅動程式已在 10 月累積更新中刪除。

 

CVE-2025-24052 的概念驗證碼已被公開。微軟已知受支援的 Windows 作業系統原生附帶的第三方  Agere Modem 驅動程式中存在漏洞。這是關於即將刪除 ltmdm64.sys 驅動程式的公告。該驅動程式已在 10 月累積更新中刪除。

 

CVE-2025-47827 正被廣泛利用。在 IGEL OS 11 之前的版本中,由於 igel-flash-driver 模組未能正確驗證加密簽名,安全啟動功能可能會被繞過。最終,攻擊者可以從未經驗證的 SquashFS 映像掛載精心設計的根檔案系統。

Server Software中度風險 中度風險權限提升
仿冒
 
開發者工具中度風險 中度風險權限提升
資料洩露
繞過保安限制
 
延伸安全性更新 (ESU)中度風險 中度風險權限提升
資料洩露
遠端執行程式碼
仿冒
阻斷服務
篡改
繞過保安限制

CVE-2025-59230 正被廣泛利用。Windows 遠端存取連線管理員中的存取控制不當,允許授權攻擊者在本機提升權限。

 

CVE-2025-24990 正被廣泛利用。微軟已知支援的 Windows 作業系統原生附帶的第三方 Agere Modem 驅動程式中存在漏洞。這是關於即將刪除 ltmdm64.sys 驅動程式的公告。該驅動程式已在 10 月累積更新中刪除。

 

CVE-2025-24052 的概念驗證碼已被公開。微軟已知受支援的 Windows 作業系統原生附帶的第三方 Agere Modem 驅動程式中存在漏洞。這是關於即將刪除 ltmdm64.sys 驅動程式的公告。該驅動程式已在 10 月累積更新中刪除。

 

CVE-2025-47827 正被廣泛利用。在 IGEL OS 11 之前的版本中,由於 igel-flash-driver 模組未能正確驗證加密簽名,安全啟動功能可能會被繞過。最終,攻擊者可以從未經驗證的 SquashFS 映像掛載精心設計的根檔案系統。

System Center中度風險 中度風險權限提升
阻斷服務
 
微軟 Office中度風險 中度風險遠端執行程式碼
資料洩露
阻斷服務
 
SQL Server低度風險 低度風險仿冒 
Apps中度風險 中度風險權限提升
仿冒
 
開源軟件低度風險 低度風險仿冒 

 

「極高度風險」產品數目:0

「高度風險」產品數目:0

「中度風險」產品數目:8

「低度風險」產品數目:2

整體「風險程度」評估:中度風險


影響

  • 遠端執行程式碼
  • 阻斷服務
  • 篡改
  • 資料洩露
  • 繞過保安限制
  • 權限提升
  • 仿冒

受影響之系統或技術

  • Azure
  • 視窗
  • Server Software
  • 開發者工具
  • 延伸安全性更新 (ESU)
  • System Center
  • 微軟 Office
  • SQL Server
  • Apps
  • 開源軟件

解決方案

在安裝軟體之前,請先瀏覽軟體供應商之網站,以獲得更多詳細資料。

  • 安裝軟件供應商提供的修補程式。

漏洞識別碼


資料來源


相關連結

Microsoft Monthly Security Update (October 2025)

Microsoft Monthly Security Update (October 2025)

Release Date: 15 Oct 2025

RISK: Medium Risk

TYPE: Operating Systems - Windows OS

Microsoft has released monthly security update for their products:

 

Vulnerable ProductRisk LevelImpactsNotes
AzureMedium Risk Medium RiskElevation of Privilege
Remote Code Execution
Spoofing
 
WindowsMedium Risk Medium RiskElevation of Privilege
Information Disclosure
Security Restriction Bypass
Remote Code Execution
Spoofing
Denial of Service
Data Manipulation

CVE-2025-59230 is being exploited in the wild. Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

 

CVE-2025-24990 is being exploited in the wild. Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumulative update.

 

Proof of Concept exploit code is publicly available for CVE-2025-24052 . Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumulative update.

 

CVE-2025-47827 is being exploited in the wild. In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image.

Server SoftwareMedium Risk Medium RiskElevation of Privilege
Spoofing
 
Developer ToolsMedium Risk Medium RiskElevation of Privilege
Information Disclosure
Security Restriction Bypass
 
Extended Security Updates (ESU)Medium Risk Medium RiskElevation of Privilege
Information Disclosure
Remote Code Execution
Spoofing
Denial of Service
Data Manipulation
Security Restriction Bypass

CVE-2025-59230 is being exploited in the wild. Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

 

CVE-2025-24990 is being exploited in the wild. Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumulative update.

 

Proof of Concept exploit code is publicly available for CVE-2025-24052 . Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumulative update.

 

CVE-2025-47827 is being exploited in the wild. In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image.

System CenterMedium Risk Medium RiskElevation of Privilege
Denial of Service
 
Microsoft OfficeMedium Risk Medium RiskRemote Code Execution
Information Disclosure
Denial of Service
 
SQL ServerLow Risk Low RiskSpoofing 
AppsMedium Risk Medium RiskElevation of Privilege
Spoofing
 
Open Source SoftwareLow Risk Low RiskSpoofing 

 

Number of 'Extremely High Risk' product(s): 0

Number of 'High Risk' product(s): 0

Number of 'Medium Risk' product(s): 8

Number of 'Low Risk' product(s): 2

Evaluation of overall 'Risk Level': Medium Risk


Impact

  • Remote Code Execution
  • Denial of Service
  • Data Manipulation
  • Information Disclosure
  • Security Restriction Bypass
  • Elevation of Privilege
  • Spoofing

System / Technologies affected

  • Azure
  • Windows
  • Server Software
  • Developer Tools
  • Extended Security Updates (ESU)
  • System Center
  • Microsoft Office
  • SQL Server
  • Apps
  • Open Source Software

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  •  Apply fixes issued by the vendor.

Vulnerability Identifier


Source


Related Link

    2025年10月13日星期一

    甲骨文 E-Business Suite 資料洩露漏洞

    甲骨文 E-Business Suite 資料洩露漏洞

    發佈日期: 2025年10月13日

    風險: 中度風險

    類型: 伺服器 - 其他伺服器

    於甲骨文 E-Business Suite 發現一個漏洞。遠端攻擊者可利用此漏洞,於目標系統觸發敏感資料洩露。


    影響

    • 資料洩露

    受影響之系統或技術

    • 甲骨文 E-Business Suite 版本 12.2.3-12.2.14

    解決方案

    在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

     

    安裝供應商提供的修補程式:


    漏洞識別碼


    資料來源


    相關連結

    Oracle E-Business Suite Information Disclosure Vulnerability

    Oracle E-Business Suite Information Disclosure Vulnerability

    Release Date: 13 Oct 2025

    RISK: Medium Risk

    TYPE: Servers - Other Servers

    A vulnerability has been identified in Oracle E-Business Suite. A remote attacker can exploit this vulnerability to trigger sensitive information disclosure on the targeted system.


    Impact

    • Information Disclosure

    System / Technologies affected

    • Oracle E-Business Suite versions 12.2.3-12.2.14

    Solutions

    Before installation of the software, please visit the vendor web-site for more details.

     

    Apply fixes issued by the vendor:


    Vulnerability Identifier


    Source


    Related Link

    2025年10月10日星期五

    GitLab 多個漏洞

    GitLab 多個漏洞

    發佈日期: 2025年10月10日

    風險: 中度風險

    類型: 伺服器 - 其他伺服器

    於 GitLab 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況及繞過保安限制。


    影響

    • 阻斷服務
    • 繞過保安限制

    受影響之系統或技術

    • GitLab Community Edition (CE) 18.4.2, 18.3.4, 18.2.8 以前的版本
    • GitLab Enterprise Edition (EE) 18.4.2, 18.3.4, 18.2.8 以前的版本

    解決方案

    在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

     

    安裝供應商提供的修補程式:


    漏洞識別碼


    資料來源


    相關連結

    GitLab Multiple Vulnerabilities

    GitLab Multiple Vulnerabilities

    Release Date: 10 Oct 2025

    RISK: Medium Risk

    TYPE: Servers - Other Servers

    Multiple vulnerabilities were identified in GitLab. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition and security restriction bypass on the targeted system.


    Impact

    • Denial of Service
    • Security Restriction Bypass

    System / Technologies affected

    • GitLab Community Edition (CE) versions prior to 18.4.2, 18.3.4, 18.2.8
    • GitLab Enterprise Edition (EE) versions prior to 18.4.2, 18.3.4, 18.2.8

    Solutions

    Before installation of the software, please visit the vendor web-site for more details.

     

    Apply fixes issued by the vendor:


    Vulnerability Identifier


    Source


    Related Link

    Juniper Junos OS 多個漏洞

    Juniper Junos OS 多個漏洞

    發佈日期: 2025年10月10日

    風險: 中度風險

    類型: 操作系統 - Network

    於 Juniper Junos OS 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行程式碼、阻斷服務狀況、洩露敏感資料、權限提升及繞過保安限制。


    影響

    • 阻斷服務
    • 資料洩露
    • 繞過保安限制
    • 權限提升
    • 遠端執行程式碼

    受影響之系統或技術

    • Junos OS
    • Junos OS Evolved

    詳情請參閱以下連結﹕

    https://supportportal.juniper.net/s/global-search/%40uri#sortCriteria=date%20descending&f-sf_articletype=Security%20Advisories&numberOfResults=25


    解決方案

    在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

     

    請參閱 2025-10 安全公告


    漏洞識別碼


    資料來源


    相關連結

    Juniper Junos OS Multiple Vulnerabilities

    Juniper Junos OS Multiple Vulnerabilities

    Release Date: 10 Oct 2025

    RISK: Medium Risk

    TYPE: Operating Systems - Networks OS

    Multiple vulnerabilities were identified in Juniper Junos OS. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution, denial of service condition, sensitive information disclosure, elevation of privilege and security restriction bypass on the targeted system.


    Impact

    • Denial of Service
    • Information Disclosure
    • Security Restriction Bypass
    • Elevation of Privilege
    • Remote Code Execution

    System / Technologies affected

    • Junos OS
    • Junos OS Evolved

    Please refer to the link below for detail:

    https://supportportal.juniper.net/s/global-search/%40uri#sortCriteria=date%20descending&f-sf_articletype=Security%20Advisories&numberOfResults=25


    Solutions

    Before installation of the software, please visit the vendor web-site for more details.

     

    Please refer to 2025-10 Security Bulletin.


    Vulnerability Identifier


    Source


    Related Link

    Microsoft Edge 多個漏洞

    Microsoft Edge 多個漏洞

    發佈日期: 2025年10月10日

    風險: 中度風險

    類型: 用戶端 - 瀏覽器

    於 Microsoft Edge 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼及阻斷服務狀況。


    影響

    • 遠端執行程式碼
    • 阻斷服務

    受影響之系統或技術

    • Microsoft Edge 141.0.3537.71 之前的版本

    解決方案

    在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

    安裝軟件供應商提供的修補程式:

    • 更新至 141.0.3537.71 或之後版本

    漏洞識別碼


    資料來源


    相關連結

    Microsoft Edge Multiple Vulnerabilities

    Microsoft Edge Multiple Vulnerabilities

    Release Date: 10 Oct 2025

    RISK: Medium Risk

    TYPE: Clients - Browsers

    Multiple vulnerabilities were identified in Microsoft Edge. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution and denial of service condition on the targeted system.


    Impact

    • Remote Code Execution
    • Denial of Service

    System / Technologies affected

    • Microsoft Edge version prior to 141.0.3537.71

    Solutions

    Before installation of the software, please visit the software vendor web-site for more details.

    Apply fixes issued by the vendor:

    • Update to version 141.0.3537.71 or later

    Vulnerability Identifier


    Source


    Related Link

    2025年10月8日星期三

    Google Chrome 多個漏洞

    Google Chrome 多個漏洞

    發佈日期: 2025年10月08日

    風險: 中度風險

    類型: 用戶端 - 瀏覽器

    於 Google Chrome 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況及遠端執行任意程式碼。


    影響

    • 遠端執行程式碼
    • 阻斷服務

    受影響之系統或技術

    • Google Chrome 141.0.7390.65 (Linux) 之前的版本
    • Google Chrome 141.0.7390.65/.66 (Mac) 之前的版本
    • Google Chrome 141.0.7390.65/.66 (Windows) 之前的版本

    解決方案

    在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

    安裝軟件供應商提供的修補程式:

    • 更新至 141.0.7390.65 (Linux) 或之後版本
    • 更新至 141.0.7390.65/.66 (Mac) 或之後版本
    • 更新至 141.0.7390.65/.66 (Windows) 或之後版本

    漏洞識別碼


    資料來源


    相關連結

    Google Chrome Multiple Vulnerabilities

    Google Chrome Multiple Vulnerabilities

    Release Date: 8 Oct 2025

    RISK: Medium Risk

    TYPE: Clients - Browsers

    Multiple vulnerabilities were identified in Google Chrome. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition and remote code execution on the targeted system.


    Impact

    • Remote Code Execution
    • Denial of Service

    System / Technologies affected

    • Google Chrome prior to 141.0.7390.65 (Linux)
    • Google Chrome prior to 141.0.7390.65/.66 (Mac)
    • Google Chrome prior to 141.0.7390.65/.66 (Windows)

    Solutions

    Before installation of the software, please visit the software vendor web-site for more details.

    Apply fixes issued by the vendor:

    • Update to version 141.0.7390.65 (Linux) or later
    • Update to version 141.0.7390.65/.66 (Mac) or later
    • Update to version 141.0.7390.65/.66 (Windows) or later

    Vulnerability Identifier


    Source


    Related Link

    Redis 產品遠端執行程式碼漏洞

    Redis 產品遠端執行程式碼漏洞

    發佈日期: 2025年10月08日

    風險: 高度風險

    類型: 伺服器 - 其他伺服器

    於 Redis 產品發現一個漏洞。遠端攻擊者可利用此漏洞,於目標系統觸發遠端執行任意程式碼。

     

    注意:

    CVE-2025-49844 正在被廣泛利用。經過驗證的使用者可以使用特製的 Lua 腳本來操縱垃圾回收器(garbage collector),觸發 UAF 並可能觸發遠端執行任意程式碼。因此,風險等級被評為高度風險。


    影響

    • 遠端執行程式碼

    受影響之系統或技術

    • 所有 Redis 軟件版本
    • 所有具備 Lua 腳本功能的 Redis OSS/CE/Stack 版本

    解決方案

    在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

     

    安裝供應商提供的修補程式:


    漏洞識別碼


    資料來源


    相關連結

    Redis Products Remote Code Execution Vulnerability

    Redis Products Remote Code Execution Vulnerability

    Release Date: 8 Oct 2025

    RISK: High Risk

    TYPE: Servers - Other Servers

    A vulnerability has been identified in Redis Products. A remote attacker could exploit this vulnerability to trigger remote code execution on the targeted system.

     

    Note:


    Impact

    • Remote Code Execution

    System / Technologies affected

    • All Redis Software releases
    • All Redis OSS/CE/Stack releases with Lua scripting

    Solutions

    Before installation of the software, please visit the vendor web-site for more details.

     

    Apply fixes issued by the vendor:


    Vulnerability Identifier


    Source


    Related Link

    三星產品多個漏洞

    三星產品多個漏洞

    發佈日期: 2025年10月08日

    風險: 中度風險

    類型: 操作系統 - 流動裝置及操作系統

    於 Samsung 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行任意程式碼、洩露敏感資料、資料篡改及繞過保安限制。


    影響

    • 遠端執行程式碼
    • 阻斷服務
    • 資料洩露
    • 繞過保安限制
    • 篡改

    受影響之系統或技術

    • 運行 Android 13, 14, 15, 16 的三星產品

    有關受影響產品,請參閱以下連結:

    https://security.samsungmobile.com/securityUpdate.smsb


    解決方案

    在安裝軟件之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

     

    安裝軟件供應商提供的修補程式:


    漏洞識別碼


    資料來源


    相關連結

    Apache Tomcat 多個漏洞

    Apache Tomcat 多個漏洞 發佈日期: 2026年08月05日 風險: 中度風險 類型: 伺服器 - 網站伺服器 於 Apache T...