Zoom¶à¿îÈí¼þÔ¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-07-17Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-13567£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
ÊÜÓ°ÏìµÄ°æ±¾
MacµÄZoom Client 4.4.53932.0709֮ǰ°æ±¾
Îó²î¸ÅÊö
ZoomÊÇÆóÒµÊÓÆµÍ¨Ñ¶ÁìÓòµÄÏòµ¼Õߣ¬£¬£¬£¬£¬ÊÇÊÓÆµºÍÒôƵ¾Û»á£¬£¬£¬£¬£¬Ì¸ÌìºÍÍøÂç×êÑлá×îÊܽӴýºÍ×î¿É¿¿µÄÔÆÆ½Ì¨Ö®Ò»¡£¡£¡£¡£¡£¡£¡£
ÔÚ7ÔÂ10ÈÕ¹ãÊܽӴýÇÒÆÕ±éʹÓõÄZoomÊÓÆµ¾Û»áÈí¼þÖÐÅû¶Òþ˽Îó²îCVE-2019-13450µÄÔÓÂҺͿֻŻ¹Ã»Óп¢Ê¡£¡£¡£¡£¡£¡£¡£Èí¼þÍâµØ×°ÖõÄwebЧÀÍÆ÷²»µ«ÔÊÐíÈκÎÍøÕ¾·¿ªÄúµÄ×°±¸ÍøÂçÉãÏñÍ·£¬£¬£¬£¬£¬²¢ÇÒ»¹¿ÉÒÔÈúڿÍÔ¶³ÌÍêÈ«¿ØÖÆÄúµÄApple MacÅÌËã»ú¡£¡£¡£¡£¡£¡£¡£
¾Ý±¨µÀ£¬£¬£¬£¬£¬ÓÃÓÚmacOSµÄ»ùÓÚÔÆµÄZoom¾Û»áƽ̨Ҳ±»·¢Ã÷ÈÝÒ×Êܵ½ÁíÒ»¸öÑÏÖØÎó²î£¨CVE-2019-13567£©µÄÓ°Ï죬£¬£¬£¬£¬¸ÃÎó²î¿ÉÄÜÔÊÐíÔ¶³Ì¹¥»÷ÕßÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£
ÕâÁ½¸öÎó²î¶¼Ô´ÓÚÒ»¸öÓÐÕùÒéµÄÍâµØWebЧÀÍÆ÷£¬£¬£¬£¬£¬ÔÚ¶Ë¿Ú19421ÉÏÔËÐУ¬£¬£¬£¬£¬Zoom¿Í»§¶Ë×°ÖÃÔÚÓû§µÄÅÌËã»úÉÏÒÔÌṩµã»÷¼ÓÈ빦Ч¡£¡£¡£¡£¡£¡£¡£Çå¾²Ñо¿Ö°Ô±Ç¿µ÷µÄÖ÷ÒªÊÇÁ½¸öÎÊÌ⣺Ê×ÏÈ£¬£¬£¬£¬£¬ÍâµØÐ§ÀÍÆ÷¡°²»Çå¾²¡±Í¨¹ýHTTPÎüÊÕÏÂÁ£¬£¬£¬£¬ÔÊÐíÈκÎÍøÕ¾ÓëÖ®½»»¥£¬£¬£¬£¬£¬Æä´Î£¬£¬£¬£¬£¬µ±Óû§´ÓÆäϵͳÖÐɾ³ýZoom¿Í»§¶Ëʱ£¬£¬£¬£¬£¬Ëü²»»á±»Ð¶ÔØ£¬£¬£¬£¬£¬ÈÃËûÃÇÓÀԶųÈõ¡£¡£¡£¡£¡£¡£¡£
ÏÂÃæÁгöµÄZoomÈí¼þ¹²ÓÐ10¸ö¸üÃû°æ±¾£¬£¬£¬£¬£¬¿ÉÔÚÊг¡ÉÏÂòµ½¡£¡£¡£¡£¡£¡£¡£ËùÓÐÕâЩÊÓÆµ¾Û»áÈí¼þ¶¼ÔÚÊÂÇ飬£¬£¬£¬£¬²¢°üÀ¨ÏàͬµÄÎó²î£¬£¬£¬£¬£¬Ê¹Óû§Ò²ÃæÁÙÔ¶³ÌºÚ¿Í¹¥»÷µÄΣº¦£º
Zhumu
Telus Meetings
BT Cloud Phone Meetings
Office Suite HD Meeting
AT&T Video Meetings
BizConf
Huihui
UMeeting
Zoom CN
AppleÒÑÍÆËÍÁËËùÓÐmacOSÓû§µÄ¸üУ¬£¬£¬£¬£¬×Ô¶¯É¾³ýZoom WebЧÀÍÆ÷¶øÎÞÐèÈκÎÓû§½»»¥¡£¡£¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
https://twitter.com/karanlyons/status/1150774640899317760¡£¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
RingCentralÐÞ²¹ÁËÎó²î£¬£¬£¬£¬£¬Çë¸üÐÂÖÁRingCentral Meetings MacOS app v7.0.151508.0712£ºhttps://support.ringcentral.com/s/article/11201-Meetings-Security-Advisory?language=en_US¡£¡£¡£¡£¡£¡£¡£
½¨ÒéÓû§Í¨¹ýÔËÐÐGitHubÉϵÄÑо¿Ö°Ô±ÌṩµÄÏÂÁîÊÖ¶¯É¾³ýÒþ²ØµÄWebЧÀÍÆ÷£ºhttps://gist.github.com/karanlyons/1fde1c63bd7bb809b04323be3f519f7e¡£¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://thehackernews.com/2019/07/zoom-video-conferencing-hacking.html


¾©¹«Íø°²±¸11010802024551ºÅ