Zoom¶à¿îÈí¼þÔ¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-07-17

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-13567£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾

MacµÄZoom Client 4.4.53932.0709֮ǰ°æ±¾


Îó²î¸ÅÊö


ZoomÊÇÆóÒµÊÓÆµÍ¨Ñ¶ÁìÓòµÄÏòµ¼Õߣ¬£¬£¬£¬£¬ÊÇÊÓÆµºÍÒôƵ¾Û»á£¬£¬£¬£¬£¬Ì¸ÌìºÍÍøÂç×êÑлá×îÊܽӴýºÍ×î¿É¿¿µÄÔÆÆ½Ì¨Ö®Ò»¡£¡£¡£¡£¡£¡£¡£


ÔÚ7ÔÂ10ÈÕ¹ãÊܽӴýÇÒÆÕ±éʹÓõÄZoomÊÓÆµ¾Û»áÈí¼þÖÐÅû¶Òþ˽Îó²îCVE-2019-13450µÄÔÓÂҺͿֻŻ¹Ã»Óп¢Ê¡£¡£¡£¡£¡£¡£¡£Èí¼þÍâµØ×°ÖõÄwebЧÀÍÆ÷²»µ«ÔÊÐíÈκÎÍøÕ¾·­¿ªÄúµÄ×°±¸ÍøÂçÉãÏñÍ·£¬£¬£¬£¬£¬²¢ÇÒ»¹¿ÉÒÔÈúڿÍÔ¶³ÌÍêÈ«¿ØÖÆÄúµÄApple MacÅÌËã»ú¡£¡£¡£¡£¡£¡£¡£


¾Ý±¨µÀ£¬£¬£¬£¬£¬ÓÃÓÚmacOSµÄ»ùÓÚÔÆµÄZoom¾Û»áƽ̨Ҳ±»·¢Ã÷ÈÝÒ×Êܵ½ÁíÒ»¸öÑÏÖØÎó²î£¨CVE-2019-13567£©µÄÓ°Ï죬£¬£¬£¬£¬¸ÃÎó²î¿ÉÄÜÔÊÐíÔ¶³Ì¹¥»÷ÕßÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£


ÕâÁ½¸öÎó²î¶¼Ô´ÓÚÒ»¸öÓÐÕùÒéµÄÍâµØWebЧÀÍÆ÷£¬£¬£¬£¬£¬ÔÚ¶Ë¿Ú19421ÉÏÔËÐУ¬£¬£¬£¬£¬Zoom¿Í»§¶Ë×°ÖÃÔÚÓû§µÄÅÌËã»úÉÏÒÔÌṩµã»÷¼ÓÈ빦Ч¡£¡£¡£¡£¡£¡£¡£Çå¾²Ñо¿Ö°Ô±Ç¿µ÷µÄÖ÷ÒªÊÇÁ½¸öÎÊÌ⣺Ê×ÏÈ£¬£¬£¬£¬£¬ÍâµØÐ§ÀÍÆ÷¡°²»Çå¾²¡±Í¨¹ýHTTPÎüÊÕÏÂÁ£¬£¬£¬£¬ÔÊÐíÈκÎÍøÕ¾ÓëÖ®½»»¥£¬£¬£¬£¬£¬Æä´Î£¬£¬£¬£¬£¬µ±Óû§´ÓÆäϵͳÖÐɾ³ýZoom¿Í»§¶Ëʱ£¬£¬£¬£¬£¬Ëü²»»á±»Ð¶ÔØ£¬£¬£¬£¬£¬ÈÃËûÃÇÓÀԶųÈõ¡£¡£¡£¡£¡£¡£¡£


ÏÂÃæÁгöµÄZoomÈí¼þ¹²ÓÐ10¸ö¸üÃû°æ±¾£¬£¬£¬£¬£¬¿ÉÔÚÊг¡ÉÏÂòµ½¡£¡£¡£¡£¡£¡£¡£ËùÓÐÕâЩÊÓÆµ¾Û»áÈí¼þ¶¼ÔÚÊÂÇ飬£¬£¬£¬£¬²¢°üÀ¨ÏàͬµÄÎó²î£¬£¬£¬£¬£¬Ê¹Óû§Ò²ÃæÁÙÔ¶³ÌºÚ¿Í¹¥»÷µÄΣº¦£º


RingCentral
Zhumu
Telus Meetings
BT Cloud Phone Meetings
Office Suite HD Meeting
AT&T Video Meetings
BizConf
Huihui
UMeeting

Zoom CN


AppleÒÑÍÆËÍÁËËùÓÐmacOSÓû§µÄ¸üУ¬£¬£¬£¬£¬×Ô¶¯É¾³ýZoom WebЧÀÍÆ÷¶øÎÞÐèÈκÎÓû§½»»¥¡£¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


POCÊÓÆµ£º

https://twitter.com/karanlyons/status/1150774640899317760¡£¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ZoomÐÞ²¹ÁËÎó²î£¬£¬£¬£¬£¬Çë¸üÐÂÖÁZoom client version 4.4.53932.0709£ºhttps://zoom.us/download¡£¡£¡£¡£¡£¡£¡£

RingCentralÐÞ²¹ÁËÎó²î£¬£¬£¬£¬£¬Çë¸üÐÂÖÁRingCentral Meetings MacOS app v7.0.151508.0712£ºhttps://support.ringcentral.com/s/article/11201-Meetings-Security-Advisory?language=en_US¡£¡£¡£¡£¡£¡£¡£


»º½â²½·¥£º

½¨ÒéÓû§Í¨¹ýÔËÐÐGitHubÉϵÄÑо¿Ö°Ô±ÌṩµÄÏÂÁîÊÖ¶¯É¾³ýÒþ²ØµÄWebЧÀÍÆ÷£ºhttps://gist.github.com/karanlyons/1fde1c63bd7bb809b04323be3f519f7e¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://thehackernews.com/2019/07/zoom-ringcentral-vulnerabilities.html 
https://thehackernews.com/2019/07/zoom-video-conferencing-hacking.html