CVE-2020-3495 | Cisco JabberÔ¶³Ì´úÂëÖ´ÐÐÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-09-03

0x00 Îó²î¸ÅÊö

CVE   ID

CVE-2020-3495

ʱ    ¼ä

2020-09-03

Àà    ÐÍ

RCE

µÈ    ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

ËùÓÐÊÊÓÃWindows Cisco Jabber¿Í»§¶Ë°æ±¾£¨12.1ÖÁ12.9£©

 

2020Äê09ÔÂ02ÈÕ£¬£¬£¬Cisco¹Ù·½ÐÞ¸´ÁËÒ»¸öÑÏÖØµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-3495£©£¬£¬£¬¸ÃÎó²îCVSSÆÀ·ÖΪ9.9·Ö¡£¡£¡£¡£

CVE-2020-3495Îó²îÓÉWatchcomµÄÇå¾²Ñо¿Ö°Ô±Olav Sortland Thoresen·¢Ã÷²¢±¨¸æ£¬£¬£¬Ë¼¿Æ²úÆ·Çå¾²ÊÂÎñÏìÓ¦ÍŶӣ¨PSIRT£©ÌåÏÖ¸ÃÎó²îÄ¿½ñÉÐδ±»ÆÕ±éʹÓᣡ£¡£¡£

0x01 Îó²îÏêÇé

 

ͼƬ4.png


 

Cisco Jabber for WindowsÊÇÒ»¿î×ÀÃæÐ­×÷Ó¦ÓóÌÐò£¬£¬£¬Ö÷ҪΪÓû§Ìṩ״̬¡¢¼´Ê±ÐÂÎÅ£¨IM£©¡¢ÐÂÎÅ¡¢×ÀÃæ¹²Ïí¡¢ÊÓÆµÒôƵ¾Û»áºÍWeb¾Û»áЧÀÍ¡£¡£¡£¡£

CVE-2020-3495ÊÇÓÉÓÚÓʼþÄÚÈÝÑéÖ¤²»×¼È·ÒýÆðµÄ¡£¡£¡£¡£¹¥»÷Õßͨ¹ýʹÓöñÒâµÄ¿ÉÀ©Õ¹ÐÂÎźÍ״̬ЭÒ飨XMPP£©ÐÂÎÅÀ´Ê¹ÓôËÎó²î£¬£¬£¬Í¨¹ýÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔÔÚδ´ò²¹¶¡µÄ Cisco Jabber for Windows µÄϵͳÉÏÖ´ÐжñÒâ´úÂë¡£¡£¡£¡£²¢ÇÒ£¬£¬£¬¸ÃÎó²îµÄʹÓò»ÐèÒªÓû§½»»¥£¬£¬£¬µ±Jabber for Windows¿Í»§¶ËÔÚºǫ́ÔËÐÐʱ¸ÃÎó²îÒ²¿É±»Ê¹Óᣡ£¡£¡£

µ«ÈôÊÇҪʹÓôËÎó²î£¬£¬£¬¹¥»÷Õß±ØÐèÄܹ»ÏòÔËÐÐWindowsµÄCisco JabberµÄ×îÖÕÓû§ÏµÍ³·¢ËÍXMPPÐÂÎÅ¡£¡£¡£¡£ÈôÀÖ³ÉʹÓôËÎó²î£¬£¬£¬»áµ¼ÖÂÓ¦ÓóÌÐòÔËÐеÄÍâµØÎļþ·¾¶Öб»ÉÏ´«í§ÒâÖ´ÐÐÎļþ£¬£¬£¬¸Ã¿ÉÖ´ÐÐÎļþ½«»áÒÔÆô¶¯Jabber¿Í»§¶ËÓ¦ÓóÌÐòµÄÓû§µÄÌØÈ¨ÔÚÓû§ÏµÍ³ÉÏÔËÐС£¡£¡£¡£

µ«½öÔÚphone-only modeģʽÏÂʹÓÃJabber²¢ÇÒûÓÐÆôÓÃXMPPÐÂÎÅЧÀÍʱϵͳ²»Ò×Êܵ½¹¥»÷£¬£¬£¬µ±JabberÉèÖÃΪʹÓóýXMPPÐÂÎÅת´ïÒÔÍâµÄÐÂÎÅת´ïЧÀÍʱ£¬£¬£¬¸ÃÎó²îÔòÎÞ·¨±»Ê¹Óᣡ£¡£¡£

0x02 ´¦Öóͷ£½¨Òé

½¨ÒéÉý¼¶µ½Êʵ±µÄ°æ±¾£º

ÊÜÓ°Ïì°æ±¾

¸üа汾

12.1

12.1.3

12.5

12.5.2

12.6

12.6.3

12.7

12.7.2

12.8

12.8.3

12.9

12.9.1

ÏÂÔØµØµã£º

https://software.cisco.com/download/home/284324806/type/284006014/release/12.6(3)

 

0x03 Ïà¹ØÐÂÎÅ

https://www.bleepingcomputer.com/news/security/cisco-fixes-critical-code-execution-bug-in-jabber-for-windows/

https://securityaffairs.co/wordpress/107834/security/cisco-jabber-for-windows-flaw.html

 

0x04 ²Î¿¼Á´½Ó

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-jabber-UyTKCPGg

0x05 ʱ¼äÏß

2020-09-02 CiscoÐû²¼Ç徲ͨ¸æ

2020-09-03 VSRCÐû²¼Ç徲ͨ¸æ



ͼƬ5.png