Ç÷ÊÆ¿Æ¼¼ÐÞ¸´ÆóÒµÇå¾²²úÆ·ÖеĶà¸öÎó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2020-03-18

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-8467£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.1£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-8468£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.0£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-8470£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º10£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-8598£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º10£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-8599£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º10£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Apex One (on premise) 2019

OfficeScan XG SP1

OfficeScan XG (non-SP)


Îó²î¸ÅÊö


¿ËÈÕ£¬£¬£¬£¬Ç÷ÊÆ¿Æ¼¼Ðû²¼Çå¾²¸üУ¬£¬£¬£¬ÐÞ¸´ÁËÁ½¸öÒÑÔÚÒ°ÍâʹÓõÄ0dayºÍÁíÍâ3¸öÑÏÖØÎó²î¡£¡£¡£¡£¡£¡£¡£¡£¸ÅÊöÈçÏ£º


CVE-2020-8467

Apex OneºÍOfficeScanµÄǨá㹤¾ß×é¼þÖеÄÎó²î£¬£¬£¬£¬¿Éµ¼ÖÂRCE£¬£¬£¬£¬¹¥»÷ÐèÒªÓû§Éí·ÝÈÏÖ¤¡£¡£¡£¡£¡£¡£¡£¡£


CVE-2020-8468

Apex OneºÍOfficeScanÊðÀíÊܵ½ÄÚÈÝÑé֤תÒåÎó²îµÄÓ°Ï죬£¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßʹÓÃijЩÊðÀí¿Í»§¶Ë×é¼þ£¬£¬£¬£¬¹¥»÷ÐèÒªÓû§Éí·ÝÈÏÖ¤¡£¡£¡£¡£¡£¡£¡£¡£


CVE-2020-8470

rend Micro Apex OneºÍOfficeScanЧÀÍÆ÷°üÀ¨Ò»¸öÒ×Êܹ¥»÷µÄЧÀÍDLLÎļþ£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃSYSTEMȨÏÞɾ³ýЧÀÍÆ÷ÉϵÄÈκÎÎļþ¡£¡£¡£¡£¡£¡£¡£¡£Ê¹ÓôËÎó²î²»ÐèÒªÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£¡£¡£¡£


CVE-2020-8598

OfficeScanЧÀÍÆ÷°üÀ¨Ò×Êܹ¥»÷µÄЧÀÍDLLÎļþ£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃSYSTEMȨÏÞÔÚÊÜÓ°ÏìµÄ×°ÖÃÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£Ê¹ÓôËÎó²î²»ÐèÒªÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£¡£¡£¡£


CVE-2020-8599

OfficeScanЧÀÍÆ÷°üÀ¨Ò»¸öÒ×Êܹ¥»÷µÄEXEÎļþ£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ý¸ÃÎļþ½«í§ÒâÊý¾ÝдÈëÊÜÓ°Ïì×°ÖõÄí§Òâ·¾¶²¢ÈƹýRootµÇ¼¡£¡£¡£¡£¡£¡£¡£¡£Ê¹ÓôËÎó²î²»ÐèÒªÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPoC/EXP¡£¡£¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ¹Ù·½ÒÑÐû²¼×îа汾ÐÞ¸´¸ÃÎó²î£¬£¬£¬£¬Á´½Ó£ºhttps://success.trendmicro.com/solution/000245571¡£¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://www.zdnet.com/article/two-trend-micro-zero-days-exploited-in-the-wild-by-hackers/