{"id":191545,"date":"2020-05-31T09:00:04","date_gmt":"2020-05-31T01:00:04","guid":{"rendered":"https:\/\/lrxjmw.cn\/?p=191545"},"modified":"2020-05-22T10:22:41","modified_gmt":"2020-05-22T02:22:41","slug":"2020-security-vulnerability","status":"publish","type":"post","link":"https:\/\/lrxjmw.cn\/2020-security-vulnerability.html","title":{"rendered":"\u5b89\u5168\u81f3\u4e0a\uff0c\u8fd1\u51e0\u5e74\u88ab\u5229\u7528\u6bd4\u8f83\u591a\u768410\u4e2a\u6f0f\u6d1e"},"content":{"rendered":"\n\n\n
\u5bfc\u8bfb<\/td>\n\u7f8e\u56fd\u7f51\u7edc\u5b89\u5168\u673a\u6784\u53d1\u5e032016\u20132019\u5e74\u88ab\u5229\u7528\u6700\u591a\u768410\u4e2a\u6f0f\u6d1e\u3002\u8fd1\u65e5\uff0c\u7f8e\u56fd\u56fd\u571f\u5b89\u5168\u90e8\uff08DHS\uff09\u7f51\u7edc\u5b89\u5168\u548c\u57fa\u7840\u8bbe\u65bd\u5b89\u5168\u673a\u6784\uff08CISA\uff0cCybersecurity\u548cInfrastructure Security Agency\uff09\u548cFBI\u8054\u5408\u53d1\u5e03\u4e86\u4e00\u4efd\u5173\u4e8e\u300a2016\u5e74-2019\u5e74\u88ab\u5229\u7528\u6700\u591a\u768410\u4e2a\u8f6f\u4ef6\u5b89\u5168\u6f0f\u6d1e\u300b\u7684\u62a5\u544a\u3002<\/strong><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n

\u7f8e\u56fd\u56fd\u571f\u5b89\u5168\u90e8(DHS)\u7f51\u7edc\u5b89\u5168\u548c\u57fa\u7840\u8bbe\u65bd\u5b89\u5168\u673a\u6784(CISA\uff0cCybersecurity\u548cInfrastructure Security Agency)\u548cFBI\u8054\u5408\u53d1\u5e03\u4e86\u4e00\u4efd\u5173\u4e8e\u300a2016\u5e74-2019\u5e74\u88ab\u5229\u7528\u6700\u591a\u768410\u4e2a\u8f6f\u4ef6\u5b89\u5168\u6f0f\u6d1e\u300b\u7684\u62a5\u544a\uff0c\u7763\u4fc3\u76f8\u5173\u673a\u6784\u5e94\u7528\u5fc5\u8981\u7684\u5b89\u5168\u66f4\u65b0\u6765\u9884\u9632\u5f53\u524d\u5e38\u89c1\u7684\u4e00\u4e9b\u653b\u51fb\u65b9\u5f0f\u3002
\n\"\"<\/p>\n

\u88ab\u5229\u7528\u6bd4\u8f83\u591a\u768410\u4e2a\u6f0f\u6d1e<\/strong><\/div>\n

\u62a5\u544a\u6307\u51fa\u8fc7\u53bb4\u5e74\u91cc(2016\u5e74-2019\u5e74)\u88ab\u5229\u7528\u6700\u591a\u768410\u4e2a\u5b89\u5168\u6f0f\u6d1e\u662f\uff1a<\/p>\n

CVE-2017-11882\uff1a<\/strong>\u5f71\u54cdMicrosoft Office 2007 SP3\/2010 SP2\/2013 SP1\/2016\u4ea7\u54c1<\/p>\n

CVE-2017-0199\uff1a<\/strong>\u5f71\u54cdMicrosoft Office 2007 SP3\/2010 SP2\/2013 SP1\/2016, Vista SP2, Server 2008 SP2, Windows 7 SP1, Windows 8.1<\/p>\n

CVE-2017-5638\uff1a<\/strong>\u5f71\u54cdApache Struts 2 2.3.32\u4e4b\u524d\u7684 2.3.x\u7248\u672c\u548c2.5.10.1\u4e4b\u524d\u76842.5.x\u7248\u672c<\/p>\n

CVE-2012-0158\uff1a<\/strong>\u5f71\u54cdMicrosoft Office 2003 SP3, 2007 SP2\u548cSP3, 2010 Gold\u548cSP1; Office 2003 Web Components SP3; SQL Server 2000 SP4, 2005 SP4,\u548c2008 SP2, SP3,\u548cR2; BizTalk Server 2002 SP1; Commerce Server 2002 SP4, 2007 SP2\u548c2009 Gold\u548cR2; Visual FoxPro 8.0 SP1\u548c9.0 SP2;Visual Basic 6.0<\/p>\n

CVE-2019-0604\uff1a<\/strong>\u5f71\u54cdMicrosoft SharePoint<\/p>\n

CVE-2017-0143\uff1a<\/strong>\u5f71\u54cdMicrosoft Windows Vista SP2\uff0cWindows Server 2008 SP2\u3001R2 SP1\uff0c Windows 7 SP1\u3001Windows 8.1\u3001Windows Server 2012 Gold\u548cR2\uff0cWindows RT 8.1\u548cWindows 10 Gold\u30011511\u548c1607\u7248\u672c\uff0c Windows Server 2016<\/p>\n

CVE-2018-4878\uff1a<\/strong>\u5f71\u54cdAdobe Flash Player 28.0.0.161\u4e4b\u524d\u7248\u672c<\/p>\n

CVE-2017-8759\uff1a<\/strong>\u5f71\u54cdMicrosoft .NET Framework 2.0\u30013.5\u30013.5.1\u30014.5.2\u30014.6\u30014.6.1\u30014.6.2 \u548c4.7\u7248\u672c<\/p>\n

CVE-2015-1641\uff1a<\/strong>\u5f71\u54cdMicrosoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2 \u548c2013 SP1, Office Web Apps Server 2010 SP2\u548c2013 SP1<\/p>\n

CVE-2018-7600\uff1a<\/strong>\u5f71\u54cdDrupal 7.58\u4e4b\u524d\u7248\u672c\u30018.3.9\u4e4b\u524d\u76848.x \u7248\u672c\u30018.4.6\u4e4b\u524d\u76848.4.x\u548c8.5.1\u4e4b\u524d\u76848.5.x \u7248\u672c<\/p>\n

\u6f0f\u6d1e\u5206\u5e03<\/strong><\/div>\n

\u7f8e\u56fd\u653f\u5e9c\u5206\u6790\u53d1\u73b0\uff0c\u4f0a\u6717\u3001\u671d\u9c9c\u548c\u4fc4\u7f57\u65af\u5229\u7528\u6bd4\u8f83\u591a\u76843\u4e2a\u6f0f\u6d1e\u662f\uff1a<\/p>\n

CVE-2017-11882<\/strong><\/p>\n

CVE-2017-0199<\/strong><\/p>\n

CVE-2012-0158<\/strong><\/p>\n

\u8fd93\u4e2a\u6f0f\u6d1e\u90fd\u662f\u5fae\u8f6fOffice Object Linking\u548cEmbedding (OLE)\u4e2d\u7684\u6f0f\u6d1e\u3002OLE\u5141\u8bb8\u6587\u6863\u4e2d\u542b\u6709\u6765\u81ea\u5176\u4ed6\u5e94\u7528\u4e2d\u5d4c\u5165\u7684\u5185\u5bb9\uff0c\u6bd4\u5982excel\u8868\u683c\u30022019\u5e74\u521d\u7684\u4e00\u9879\u7814\u7a76\u4e5f\u8868\u660e\uff0c\u653b\u51fb\u8005\u5229\u7528\u6700\u591a\u7684\u6f0f\u6d1e\u5b58\u5728\u4e8e\u5fae\u8f6f\u548cAdobe Flash\u4ea7\u54c1\u4e2d\uff0c\u53ef\u80fd\u662f\u56e0\u4e3a\u8fd9\u4e9b\u4ea7\u54c1\u88ab\u5e7f\u6cdb\u5f15\u7528\u3002\u6392\u540d\u7b2c\u4e8c\u7684\u662fweb\u6846\u67b6 Apache Struts\u3002<\/p>\n

2020\u5e74\u6f0f\u6d1e\u5229\u7528\u60c5\u51b5<\/strong><\/div>\n

\u9664\u4e862016\u5e74\u52302019\u5e74\u88ab\u5229\u7528\u6bd4\u8f83\u591a\u768410\u4e2a\u6f0f\u6d1e\u5916\uff0c\u7f8e\u56fd\u653f\u5e9c\u8fd8\u62a5\u544a\u4e862020\u5e74\u88ab\u5229\u7528\u6bd4\u8f83\u591a\u7684\u4e00\u4e9b\u6f0f\u6d1e\u4ee5\u53ca\u7f51\u7edc\u653b\u51fb\u8d8b\u52bf\u3002<\/p>\n

1\u3001VPN\u6f0f\u6d1e\u3002<\/strong><\/span><\/div>\n

\u4eca\u5e74\u4ee5\u6765\uff0c\u6076\u610f\u7f51\u7edc\u653b\u51fb\u8005\u5f00\u59cb\u4e0d\u65ad\u653b\u51fb\u672a\u4fee\u590d\u7684VPN\u6f0f\u6d1e\uff1a<\/p>\n

CVE-2019-19781\uff1a<\/strong>Citrix VPN\u5e94\u7528\u4e2d\u7684\u4efb\u610f\u4ee3\u7801\u6267\u884c\u6f0f\u6d1e<\/p>\n

CVE-2019-11510\uff1a<\/strong>Pulse Secure VPN\u670d\u52a1\u5668\u4e2d\u7684\u4e00\u4e2a\u4efb\u610f\u6587\u4ef6\u8bfb\u6f0f\u6d1e<\/p>\n

2\u3001office 365\u6f0f\u6d1e\u3002<\/strong><\/span><\/div>\n

2020\u5e743\u6708\u4ee5\u6765\u8fdc\u7a0b\u529e\u516c\u8f6f\u4ef6\u4f7f\u7528\u91cf\u6fc0\u589e\u3002\u653b\u51fb\u8005\u5f00\u59cb\u5229\u7528office 365\u8f6f\u4ef6\u7684\u5b89\u5168\u6f0f\u6d1e\uff0c\u5bf9\u76f8\u5173\u5b89\u5168\u914d\u7f6e\u8fdb\u884c\u626b\u63cf\u548c\u53d1\u8d77\u653b\u51fb\u3002<\/p>\n

3\u3001\u52d2\u7d22\u8f6f\u4ef6\u653b\u51fb\u3002<\/strong><\/span><\/div>\n

\u5458\u5de5\u5bf9\u793e\u4f1a\u5de5\u7a0b\u653b\u51fb\u4e86\u89e3\u4e0d\u8db3\u3001\u7f3a\u4e4f\u7cfb\u7edf\u6062\u590d\u548c\u5e94\u6025\u65b9\u6848\uff0c2020\u5e74\u4f01\u4e1a\u906d\u53d7\u52d2\u7d22\u8f6f\u4ef6\u653b\u51fb\u53ef\u80fd\u4f1a\u6210\u4e3a\u4e00\u4e2a\u65b0\u7684\u8d8b\u52bf\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"

\u7f8e\u56fd\u56fd\u571f\u5b89\u5168\u90e8(DHS)\u7f51\u7edc\u5b89\u5168\u548c\u57fa\u7840\u8bbe\u65bd\u5b89\u5168\u673a\u6784(CISA\uff0cCybersecurity\u548cInfrastruc […]<\/p>\n","protected":false},"author":370,"featured_media":158090,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[21],"tags":[],"class_list":["post-191545","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"acf":[],"_links":{"self":[{"href":"https:\/\/lrxjmw.cn\/wp-json\/wp\/v2\/posts\/191545","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lrxjmw.cn\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lrxjmw.cn\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lrxjmw.cn\/wp-json\/wp\/v2\/users\/370"}],"replies":[{"embeddable":true,"href":"https:\/\/lrxjmw.cn\/wp-json\/wp\/v2\/comments?post=191545"}],"version-history":[{"count":5,"href":"https:\/\/lrxjmw.cn\/wp-json\/wp\/v2\/posts\/191545\/revisions"}],"predecessor-version":[{"id":192217,"href":"https:\/\/lrxjmw.cn\/wp-json\/wp\/v2\/posts\/191545\/revisions\/192217"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lrxjmw.cn\/wp-json\/wp\/v2\/media\/158090"}],"wp:attachment":[{"href":"https:\/\/lrxjmw.cn\/wp-json\/wp\/v2\/media?parent=191545"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lrxjmw.cn\/wp-json\/wp\/v2\/categories?post=191545"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lrxjmw.cn\/wp-json\/wp\/v2\/tags?post=191545"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}