
轉發國家資通安全研究院漏洞警訊公告,請同仁儘速確認並進行更新或修補作業,以降低相關資安風險。
1.OpenSSH存在高風險安全漏洞(CVE-2024-6387)
■研究人員發現OpenSSH存在競爭條件(Race Condition)漏洞(CVE-2024-6387),允許未經身分鑑別之遠端攻擊者可利用此漏洞執行任意程式碼,該漏洞已遭駭客利用,請儘速確認並進行修補。
■處置建議:請升級OpenSSH至9.8p1(含)以上版本
2.GeoServer存在高風險安全漏洞(CVE-2024-36401)
■研究人員發現GeoServer存在程式碼注入(Code Injection)漏洞(CVE-2024-36401),未經身分鑑別之遠端攻擊者可利用此漏洞遠端執行任意程式碼。該漏洞之概念驗證(PoC)已被公開,請儘速確認並進行修補。
■處置建議:
官方已針對漏洞釋出修復更新,請參考官方說明進行更新,網址如下:https://github.com/advisories/GHSA-6jj6-gm7p-fcvv
3.Microsoft Windows MSHTML Platform存在高風險安全漏洞(CVE-2024-38112)
■研究人員發現Microsoft Windows MSHTML Platform存在遠端執行程式碼(Remote Code Execution)漏洞(CVE-2024-38112),允許未經身分鑑別之遠端攻擊者誘騙使用者下載惡意檔案後,利用此漏洞執行任意程式碼。該漏洞已遭駭客利用,請儘速確認並進行修補。
■處置建議:
官方已針對漏洞釋出修復更新,請參考官方說明進行更新,網址如下:https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38112
4.Microsoft Windows Hyper-V存在高風險安全漏洞(CVE-2024-38080)
■研究人員發現Microsoft Windows Hyper-V存在本機提權(Local Privilege Escalation)漏洞(CVE-2024-38080),已取得一般權限之本機端攻擊者可利用此漏洞提升至系統權限。該漏洞已遭駭客利用,請儘速確認並進行修補。
■處置建議:
官方已針對漏洞釋出修復更新,請參考官方說明進行更新,網址如下:https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38080
5.相關文章:
■ https://www.nics.nat.gov.tw/core_business/information_security_information_sharing/Vulnerability_Alert_Announcements/1283/
■ https://www.nics.nat.gov.tw/core_business/information_security_information_sharing/Vulnerability_Alert_Announcements/1284/
■ https://www.nics.nat.gov.tw/core_business/information_security_information_sharing/Vulnerability_Alert_Announcements/1286/
■ https://www.nics.nat.gov.tw/core_business/information_security_information_sharing/Vulnerability_Alert_Announcements/1287/
若有資安相關問題,請洽電子計算機中心:
游順發組長 6209 rogeryu@mail.ntust.edu.tw
張云蘋 6929 applechang@mail.ntust.edu.tw
【Security】Vulnerability warning: OpenSSH, GeoServer, and Microsoft Windows Hyper-V have high-risk security vulnerabilities.
Hello everyone:
Forward the vulnerability warning announcement of the National Information Security Research Institute, and ask colleagues to confirm and update or patch it as soon as possible to reduce related information security risks.
1. OpenSSH has a high-risk security vulnerability (CVE-2024-6387)
■ Researchers have discovered that OpenSSH has a race condition vulnerability (CVE-2024-6387), which allows unauthenticated remote attackers to use this vulnerability to execute arbitrary code. This vulnerability has been exploited by hackers. Please try to Confirm and fix quickly.
■ Disposal suggestion: Please upgrade OpenSSH to version 9.8p1 (inclusive) or above.
2. GeoServer has a high-risk security vulnerability (CVE-2024-36401)
■ Researchers discovered that GeoServer has a code injection vulnerability (CVE-2024-36401). An unauthenticated remote attacker can use this vulnerability to remotely execute arbitrary code. The proof of concept (PoC) of this vulnerability has been made public. Please confirm and patch it as soon as possible.
■ Disposal suggestions:
The official has released a fix update for the vulnerability. Please refer to the official instructions to update. Link: https://github.com/advisories/GHSA-6jj6-gm7p-fcvv
3. Microsoft Windows MSHTML Platform has a high-risk security vulnerability (CVE-2024-38112)
■ Researchers have discovered a Remote Code Execution vulnerability (CVE-2024-38112) in the Microsoft Windows MSHTML Platform, which allows unauthenticated remote attackers to trick users into downloading malicious files and then use this vulnerability to execute arbitrary commands. Program code. This vulnerability has been exploited by hackers, please confirm and patch it as soon as possible.
■ Disposal suggestions:
The official has released a fix update for the vulnerability. Please refer to the official instructions to update.
Link: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38112
4. Microsoft Windows Hyper-V has a high-risk security vulnerability (CVE-2024-38080)
■ Researchers have discovered that Microsoft Windows Hyper-V has a Local Privilege Escalation vulnerability (CVE-2024-38080). A local-side attacker who has obtained general privileges can use this vulnerability to escalate to system privileges. This vulnerability has been exploited by hackers, please confirm and patch it as soon as possible.
■ Disposal suggestions:
The official has released a fix update for the vulnerability. Please refer to the official instructions to update.
Link: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38080
5. Related Articles:
■ https://www.nics.nat.gov.tw/core_business/information_security_information_sharing/Vulnerability_Alert_Announcements/1283/
■ https://www.nics.nat.gov.tw/core_business/information_security_information_sharing/Vulnerability_Alert_Announcements/1284/
■ https://www.nics.nat.gov.tw/core_business/information_security_information_sharing/Vulnerability_Alert_Announcements/1286/
■ https://www.nics.nat.gov.tw/core_business/information_security_information_sharing/Vulnerability_Alert_Announcements/1287/
For more question about information security, please directly consult with Computer Center, at rogeryu@mail.ntust.edu.tw or applechang@mail.ntust.edu.tw