【資安通知】高風險0-day及遠端漏洞,請確實進行更新作業。【Information Security Notice】High-risk 0-day and remote vulnerabilities, please make sure to update.
各位師長、同仁、同學好:
1.Microsoft 已推出 2023 年 12 月例行資安更新修補包「Patch Tuesday」,共修復 34 個資安漏洞;其中含有 1 個是屬於已遭駭侵者用於攻擊的 0-day 漏洞。
2.WordPress 備份用外掛程式 Backup Migration 中的嚴重漏洞,駭侵者可藉以遠端執行任意程式碼。
3.Google接獲外部組織通報,發現Chrome瀏覽器具有高風險的0-day(漏洞編號:CVE-2024-0519),立即進行緊急搶修作業,已同步向Windows、Mac與Linux三大系統用戶釋出更新版本,分別為分別為「120.0.6099.224/225」、「120.0.6099.234」與「120.0.6099.224」。
如使用者尚未接獲系統更新通知,也可透過手動更新的方式,確保設備處於最新版本的狀態,降低個資遭盜取的資安風險。
■以windows作業系統為例,Chrome瀏覽器手動更新方式如下:
→開啟Chrome瀏覽器 >> 螢幕左上方的「...」圖示 >> 選擇「設定」選項
→於設定頁面左側列表中選擇「關於Chrome」 >> 點選後,系統即自動進行更新作業
→完成更新後按下「重新啟動」按鈕 >> 重新啟動Chrome瀏覽器,即完成更新作業。
■確認Chrome瀏覽器版本的方式:開啟Chrome瀏覽器 >> 螢幕左上方「...」圖示>> 說明 >> 關於Chrome >> 頁面顯示Chrome瀏覽器版本資訊
相關參考資訊:
https://www.twcert.org.tw/tw/cp-104-7651-6abff-1.html
https://www.twcert.org.tw/tw/cp-104-7653-0096a-1.html
https://www.twcert.org.tw/tw/cp-104-7663-64a87-1.html
若有資安相關問題,請洽電子計算機中心:
游順發組長 6209 rogeryu@mail.ntust.edu.tw
張云蘋 6929 applechang@mail.ntust.edu.tw
【Information Security Notice】High-risk 0-day and remote vulnerabilities, please make sure to update.
Hello everyone:
1. Microsoft launched the December 2023 routine security update patch package "Patch Tuesday", which fixed a total of 34 security vulnerabilities; including 1 0day vulnerability that has been exploited by hackers.
2. There is a serious vulnerability in the WordPress backup plug-in Backup Migration, which allows hackers to remotely execute arbitrary code.
3. Google received notification from an external organization and found that the Chrome browser has a high-risk 0day (vulnerability number: CVE-2024-0519). Emergency repair operations were carried out immediately, and the vulnerability was simultaneously released to Windows, Mac and Linux system users. Updated versions have been released, namely "120.0.6099.224/225", "120.0.6099.234" and "120.0.6099.224".
If the user has not received a system update notification, they can also manually update to ensure that the device is in the latest version and reduce the security risk of personal information being stolen.
Related Articles:
https://www.twcert.org.tw/tw/cp-104-7651-6abff-1.html
https://www.twcert.org.tw/tw/cp-104-7653-0096a-1.html
https://www.twcert.org.tw/tw/cp-104-7663-64a87-1.html
For more question about information security, please directly consult with Computer Center, at rogeryu@mail.ntust.edu.tw or applechang@mail.ntust.edu.tw
