Zoom¶à¿îÈí¼þÔ¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-07-17·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-13567£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
ÊÜÓ°ÏìµÄ°æ±¾
MacµÄZoom Client 4.4.53932.0709֮ǰ°æ±¾
·ì϶¸ÅÊö
ZoomÊÇÆóÒµÊÓÆµÍ¨Ñ¶ÁìÓòµÄ¸¨µ¼Õߣ¬ÊÇÊÓÆµºÍÒôƵ»áÒ飬̸ÌìºÍÍøÂç×êÑлá×îÊÜÓ½ÓºÍ×î¿¿µÃסµÄÔÆÆ½Ì¨Ö®Ò»¡£
ÔÚ7ÔÂ10ÈÕ¹ãÊÜÓ½ÓÇÒ¿í·ºÊ¹ÓõÄZoomÊÓÆµ»áÒéÈí¼þÖÐÅû¶ÒþÖÔ·ì϶CVE-2019-13450µÄ»ìÂҺͷ¢¼±»¹Ã»ÓÐʵÏÖ¡£Èí¼þ±¾µØ×°ÖõÄweb·þÎñÆ÷²»½öÔÊÐíÈκÎÍøÕ¾´ò¿ªÄúµÄÉè±¸ÍøÂçÉãÏñÍ·£¬²¢ÇÒ»¹Äܹ»ÈúڿÍÔ¶³ÌÆëÈ«½ÚÔìÄúµÄApple MacÍÆËã»ú¡£
¾Ý±¨Â·£¬ÓÃÓÚmacOSµÄ»ùÓÚÔÆµÄZoom»áÒéÆ½Ì¨Ò²±»·¢ÏÖÈÝÒ×Êܵ½ÁíÒ»¸öÑϳÁ·ì϶£¨CVE-2019-13567£©µÄÓ°Ï죬¸Ã·ì϶¿ÉÄÜÔÊÐíÔ¶³Ì¹¥»÷ÕßÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£
ÕâÁ½¸ö·ì϶¶¼Ô´ÓÚÒ»¸öÓÐÕùÒéµÄ±¾µØWeb·þÎñÆ÷£¬ÔÚ¶Ë¿Ú19421ÉÏÔËÐУ¬Zoom¿Í»§¶Ë×°ÖÃÔÚÓû§µÄÍÆËã»úÉÏÒÔÌṩµã»÷²ÎÓëÖ°ÄÜ¡£°²È«×êÑÐÈËԱǿµ÷µÄÖØÒªÊÇÁ½¸öÎÊÌ⣺Ê×ÏÈ£¬±¾µØ·þÎñÆ÷¡°²»°²È«¡±Í¨¹ýHTTP½Ó¹ÜºÅÁÔÊÐíÈκÎÍøÕ¾ÓëÖ®½»»¥£¬Æä´Î£¬µ±Óû§´ÓÆäϵͳÖÐɾ³ýZoom¿Í»§¶Ëʱ£¬Ëü²»»á±»Ð¶ÔØ£¬ÈÃËûÃÇʼÖÕ´àÈõ¡£
ÏÂÃæÁгöµÄZoomÈí¼þ¹²ÓÐ10¸ö¸ÄÃû°æ±¾£¬¿ÉÔÚÊг¡ÉÏÂòµ½¡£ËùÓÐÕâЩÊÓÆµ»áÒéÈí¼þ¶¼ÔÚ¹¤×÷£¬²¢Ô̺¬Ò»ÑùµÄ·ì϶£¬Ê¹Óû§Ò²Ãæ¶ÔÔ¶³ÌºÚ¿Í¹¥»÷µÄ·çÏÕ£º
Zhumu
Telus Meetings
BT Cloud Phone Meetings
Office Suite HD Meeting
AT&T Video Meetings
BizConf
Huihui
UMeeting
Zoom CN
AppleÒÑÍÆËÍÁËËùÓÐmacOSÓû§µÄ¸üУ¬×Ô¶¯É¾³ýZoom Web·þÎñÆ÷¶øÎÞÐèÈκÎÓû§½»»¥¡£
·ì϶ÑéÖ¤
https://twitter.com/karanlyons/status/1150774640899317760¡£
½¨¸´½¨Òé
RingCentral½¨²¹ÁË·ì϶£¬Çë¸üÐÂÖÁRingCentral Meetings MacOS app v7.0.151508.0712£ºhttps://support.ringcentral.com/s/article/11201-Meetings-Security-Advisory?language=en_US¡£
½¨ÒéÓû§Í¨¹ýÔËÐÐGitHubÉϵÄ×êÑÐÈËÔ±ÌṩµÄºÅÁîÊÖ¶¯É¾³ý°µ²ØµÄWeb·þÎñÆ÷£ºhttps://gist.github.com/karanlyons/1fde1c63bd7bb809b04323be3f519f7e¡£
²Î¿¼Á´½Ó
https://thehackernews.com/2019/07/zoom-video-conferencing-hacking.html


¾©¹«Íø°²±¸11010802024551ºÅ