΢ÈíAndroid°æOutlook XSSÎó²î

Ðû²¼Ê±¼ä 2019-06-22


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


Åä¾°ÐÎò


΢ÈíÐû²¼Android°æOutlookÇå¾²¸üУ¬£¬£¬ÐÞ¸´Ò»¸ö´æ´¢ÐÍXSSÎó²î£¨CVE-2019-1105 £©¡£ ¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢ËͶñÒâµç×ÓÓʼþ´¥·¢¸ÃÎó²î£¬£¬£¬´Ó¶øÔÚÄ¿µÄ×°±¸ÉÏÖ´ÐжñÒâµÄÓ¦ÓÃÄÚ¿Í»§¶Ë´úÂë¡£ ¡£¡£¡£


Îó²îÁбí


CVE ID  £º   CVE-2019-1105
Îó²îÆ·¼¶£º   ÖÐΣ
CVSSÆÀ·Ö£º   ÔÝÎÞ
Ó°Ïì¹æÄ££º   Outlook for Android 3.0.88֮ǰµÄ°æ±¾

Îó²îÏêÇé


ƾ֤΢ÈíÐû²¼µÄÇ徲ͨ¸æ£¬£¬£¬Outlook for Android 3.0.88֮ǰµÄ°æ±¾±£´æÒ»¸ö´æ´¢ÐÍXSSÎó²î£¨CVE-2019-1105£©¡£ ¡£¡£¡£¸ÃÎó²îÓëAPPÆÊÎö´«Èëµç×ÓÓʼþµÄ·½·¨ÓйØ£¬£¬£¬¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿Éͨ¹ýÏòÄ¿µÄ·¢ËͶñÒâµç×ÓÓʼþÀ´Ê¹ÓôËÎó²î¡£ ¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÄÜ»á¶ÔÊÜÓ°ÏìµÄϵͳִÐпçÕ¾¾ç±¾¹¥»÷£¬£¬£¬²¢ÔÚÄ¿½ñÓû§µÄÇå¾²ÉÏÏÂÎÄÖÐÔËÐо籾¡£ ¡£¡£¡£´ËÇå¾²¸üÐÂͨ¹ý¸üÕýOutlook for AndroidÆÊÎöÌØ¶¨µç×ÓÓʼþµÄ·½·¨À´ÐÞ¸´¸ÃÎó²î¡£ ¡£¡£¡£


΢Èí³Æ¸ÃÎó²îÊÇÓɶà¸öÇå¾²Ñо¿Ö°Ô±×ÔÁ¦±¨¸æµÄ£¬£¬£¬²¢ÇÒ¿ÉÄܻᵼÖÂÓÕÆ­ÀàÐ͵Ĺ¥»÷¡£ ¡£¡£¡£´ËÎó²îµÄÏêϸÊÖÒÕϸ½Ú»ò¿´·¨ÑéÖ¤ÉÐδ¹ûÕæÐû²¼¡£ ¡£¡£¡£ÏÖÔÚ΢ÈíÉÐδ·¢Ã÷Óë´ËÎó²îÓйصÄÈκι¥»÷ÊÂÎñ¡£ ¡£¡£¡£

ÐÞ¸´½¨Òé


ÈôÊÇÓû§µÄAndroid×°±¸ÉÐδ×Ô¶¯¸üУ¬£¬£¬½¨ÒéÓû§´ÓGoogle PlayÊÐËÁÊÖ¶¯¸üÐÂOutlook APP¡£ ¡£¡£¡£

²Î¿¼Á´½Ó


https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1105
https://thehackernews.com/2019/06/outlook-app-android.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1105