【資安/Security】Microsoft Windows、Google Chrome、Microsoft Edge等軟體存在高風險安全漏洞,請同仁儘速確認並進行更新或修補作業。
轉發國家資通安全研究院漏洞警訊公告,請同仁儘速確認並進行更新或修補作業,以降低相關資安風險。
1.Microsoft Windows存在高風險安全漏洞(CVE-2024-21338)
●研究人員發現Microsoft Windows作業系統的AppLocker安全功能存在本機提權漏洞(CVE-2024-21338),允許完成身分鑑別的本機端攻擊者,利用此漏洞提升至系統權限。該漏洞目前已遭駭客利用,請儘速確認並進行修補。
2.Google Chrome、Microsoft Edge、Brave、Opera及Vivaldi等瀏覽器存在安全漏洞(CVE-2024-0519)
●研究人員發現Google Chrome、Microsoft Edge、Brave、Opera及Vivaldi等瀏覽器存在越界記憶體存取漏洞(CVE-2024-0519),攻擊者可利用此漏洞於遠端執行任意程式碼,請儘速確認並進行修補。
3.Fortinet FortiOS與FortiProxy存在高風險安全漏洞(CVE-2024-21762)
●研究人員發現Fortinet FortiOS與FortiProxy存在越界寫入(Out-of-Bounds Write)漏洞(CVE-2024-21762),允許未經身分鑑別的遠端攻擊者經由特製之HTTP請求,執行任意程式碼或命令。該漏洞目前已遭駭客利用,請儘速確認並進行修補。
4.QNAP OS存在高風險安全漏洞(CVE-2024-21899)
●研究人員發現QNAP OS存在不當驗證(Improper Authentication)漏洞(CVE-2024-21899),遠端攻擊者可利用此漏洞繞過身分鑑別,取得系統控制,請儘速確認並進行修補。
相關參考資訊:
■ https://www.nics.nat.gov.tw/core_business/information_security_information_sharing/Vulnerability_Alert_Announcements/1257/
■ https://www.nics.nat.gov.tw/core_business/information_security_information_sharing/Vulnerability_Alert_Announcements/1254/
■ https://www.nics.nat.gov.tw/core_business/information_security_information_sharing/Vulnerability_Alert_Announcements/1256/
■ https://www.nics.nat.gov.tw/core_business/information_security_information_sharing/Vulnerability_Alert_Announcements/1258/
若有資安相關問題,請洽電子計算機中心:
游順發組長 6209 rogeryu@mail.ntust.edu.tw
張云蘋 6929 applechang@mail.ntust.edu.tw
【Security】
Hello everyone:
Microsoft Windows, Google Chrome, Microsoft Edge and other software have high-risk security vulnerabilities. Colleagues are requested to confirm and update or patch as soon as possible.
1. Microsoft Windows has a high-risk security vulnerability (CVE-2024-21338)
● Researchers discovered that the AppLocker security function of the Microsoft Windows operating system has a local privilege escalation vulnerability (CVE-2024-21338), which allows local attackers who have completed authentication to use this vulnerability to escalate system privileges. This vulnerability has been exploited by hackers, please confirm and patch it as soon as possible.
2. There are security vulnerabilities in browsers such as Google Chrome, Microsoft Edge, Brave, Opera and Vivaldi (CVE-2024-0519)
● Researchers have discovered that browsers such as Google Chrome, Microsoft Edge, Brave, Opera and Vivaldi have an out-of-bounds memory access vulnerability (CVE-2024-0519). An attacker can use this vulnerability to execute arbitrary code remotely. Please hurry up Confirm and patch.
3. Fortinet FortiOS and FortiProxy have high-risk security vulnerabilities (CVE-2024-21762)
● Researchers discovered that Fortinet FortiOS and FortiProxy have an Out-of-Bounds Write vulnerability (CVE-2024-21762), which allows an unauthenticated remote attacker to execute arbitrary code or Order. This vulnerability has been exploited by hackers, please confirm and patch it as soon as possible.
4. QNAP OS has a high-risk security vulnerability (CVE-2024-21899)
● Researchers have discovered that QNAP OS has an Improper Authentication vulnerability (CVE-2024-21899). Remote attackers can use this vulnerability to bypass identity authentication and gain system control. Please confirm and patch it as soon as possible.
Related Articles:
■ https://www.nics.nat.gov.tw/core_business/information_security_information_sharing/Vulnerability_Alert_Announcements/1257/
■ https://www.nics.nat.gov.tw/core_business/information_security_information_sharing/Vulnerability_Alert_Announcements/1254/
■ https://www.nics.nat.gov.tw/core_business/information_security_information_sharing/Vulnerability_Alert_Announcements/1256/
■ https://www.nics.nat.gov.tw/core_business/information_security_information_sharing/Vulnerability_Alert_Announcements/1258/
For more question about information security, please directly consult with Computer Center, at rogeryu@mail.ntust.edu.tw or applechang@mail.ntust.edu.tw
