Zoom¶à¿îÈí¼þÔ¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-07-17

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-13567£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾

MacµÄZoom Client 4.4.53932.0709֮ǰ°æ±¾


Îó²î¸ÅÊö


ZoomÊÇÆóÒµÊÓÆµÍ¨Ñ¶ÁìÓòµÄÏòµ¼Õߣ¬£¬£¬£¬£¬£¬ÊÇÊÓÆµºÍÒôƵ¾Û»á£¬£¬£¬£¬£¬£¬Ì¸ÌìºÍÍøÂç×êÑлá×îÊܽӴýºÍ×î¿É¿¿µÄÔÆÆ½Ì¨Ö®Ò»¡£¡£¡£ ¡£¡£


ÔÚ7ÔÂ10ÈÕ¹ãÊܽӴýÇÒÆÕ±éʹÓõÄZoomÊÓÆµ¾Û»áÈí¼þÖÐÅû¶Òþ˽Îó²îCVE-2019-13450µÄÔÓÂҺͿֻŻ¹Ã»Óп¢Ê¡£¡£¡£ ¡£¡£Èí¼þÍâµØ×°ÖõÄwebЧÀÍÆ÷²»µ«ÔÊÐíÈκÎÍøÕ¾·­¿ªÄúµÄ×°±¸ÍøÂçÉãÏñÍ·£¬£¬£¬£¬£¬£¬²¢ÇÒ»¹¿ÉÒÔÈúڿÍÔ¶³ÌÍêÈ«¿ØÖÆÄúµÄApple MacÅÌËã»ú¡£¡£¡£ ¡£¡£


¾Ý±¨µÀ£¬£¬£¬£¬£¬£¬ÓÃÓÚmacOSµÄ»ùÓÚÔÆµÄZoom¾Û»áƽ̨Ҳ±»·¢Ã÷ÈÝÒ×Êܵ½ÁíÒ»¸öÑÏÖØÎó²î£¨CVE-2019-13567£©µÄÓ°Ï죬£¬£¬£¬£¬£¬¸ÃÎó²î¿ÉÄÜÔÊÐíÔ¶³Ì¹¥»÷ÕßÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£ ¡£¡£


ÕâÁ½¸öÎó²î¶¼Ô´ÓÚÒ»¸öÓÐÕùÒéµÄÍâµØWebЧÀÍÆ÷£¬£¬£¬£¬£¬£¬ÔÚ¶Ë¿Ú19421ÉÏÔËÐУ¬£¬£¬£¬£¬£¬Zoom¿Í»§¶Ë×°ÖÃÔÚÓû§µÄÅÌËã»úÉÏÒÔÌṩµã»÷¼ÓÈ빦Ч¡£¡£¡£ ¡£¡£Çå¾²Ñо¿Ö°Ô±Ç¿µ÷µÄÖ÷ÒªÊÇÁ½¸öÎÊÌ⣺Ê×ÏÈ£¬£¬£¬£¬£¬£¬ÍâµØÐ§ÀÍÆ÷¡°²»Çå¾²¡±Í¨¹ýHTTPÎüÊÕÏÂÁ£¬£¬£¬£¬£¬ÔÊÐíÈκÎÍøÕ¾ÓëÖ®½»»¥£¬£¬£¬£¬£¬£¬Æä´Î£¬£¬£¬£¬£¬£¬µ±Óû§´ÓÆäϵͳÖÐɾ³ýZoom¿Í»§¶Ëʱ£¬£¬£¬£¬£¬£¬Ëü²»»á±»Ð¶ÔØ£¬£¬£¬£¬£¬£¬ÈÃËûÃÇÓÀԶųÈõ¡£¡£¡£ ¡£¡£


ÏÂÃæÁгöµÄZoomÈí¼þ¹²ÓÐ10¸ö¸üÃû°æ±¾£¬£¬£¬£¬£¬£¬¿ÉÔÚÊг¡ÉÏÂòµ½¡£¡£¡£ ¡£¡£ËùÓÐÕâЩÊÓÆµ¾Û»áÈí¼þ¶¼ÔÚÊÂÇ飬£¬£¬£¬£¬£¬²¢°üÀ¨ÏàͬµÄÎó²î£¬£¬£¬£¬£¬£¬Ê¹Óû§Ò²ÃæÁÙÔ¶³ÌºÚ¿Í¹¥»÷µÄΣº¦£º


RingCentral
Zhumu
Telus Meetings
BT Cloud Phone Meetings
Office Suite HD Meeting
AT&T Video Meetings
BizConf
Huihui
UMeeting

Zoom CN


AppleÒÑÍÆËÍÁËËùÓÐmacOSÓû§µÄ¸üУ¬£¬£¬£¬£¬£¬×Ô¶¯É¾³ýZoom WebЧÀÍÆ÷¶øÎÞÐèÈκÎÓû§½»»¥¡£¡£¡£ ¡£¡£


Îó²îÑéÖ¤


POCÊÓÆµ£º

https://twitter.com/karanlyons/status/1150774640899317760¡£¡£¡£ ¡£¡£


ÐÞ¸´½¨Òé


ZoomÐÞ²¹ÁËÎó²î£¬£¬£¬£¬£¬£¬Çë¸üÐÂÖÁZoom client version 4.4.53932.0709£ºhttps://zoom.us/download¡£¡£¡£ ¡£¡£

RingCentralÐÞ²¹ÁËÎó²î£¬£¬£¬£¬£¬£¬Çë¸üÐÂÖÁRingCentral Meetings MacOS app v7.0.151508.0712£ºhttps://support.ringcentral.com/s/article/11201-Meetings-Security-Advisory?language=en_US¡£¡£¡£ ¡£¡£


»º½â²½·¥£º

½¨ÒéÓû§Í¨¹ýÔËÐÐGitHubÉϵÄÑо¿Ö°Ô±ÌṩµÄÏÂÁîÊÖ¶¯É¾³ýÒþ²ØµÄWebЧÀÍÆ÷£ºhttps://gist.github.com/karanlyons/1fde1c63bd7bb809b04323be3f519f7e¡£¡£¡£ ¡£¡£


²Î¿¼Á´½Ó


https://thehackernews.com/2019/07/zoom-ringcentral-vulnerabilities.html 
https://thehackernews.com/2019/07/zoom-video-conferencing-hacking.html