CVE-2020-3495 | Cisco JabberÔ¶³Ì´úÂëÖ´ÐÐÎó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-09-030x00 Îó²î¸ÅÊö
CVE ID | CVE-2020-3495 | ʱ ¼ä | 2020-09-03 |
Àà ÐÍ | RCE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | ËùÓÐÊÊÓÃWindows Cisco Jabber¿Í»§¶Ë°æ±¾£¨12.1ÖÁ12.9£© |
2020Äê09ÔÂ02ÈÕ£¬£¬£¬£¬Cisco¹Ù·½ÐÞ¸´ÁËÒ»¸öÑÏÖØµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-3495£©£¬£¬£¬£¬¸ÃÎó²îCVSSÆÀ·ÖΪ9.9·Ö¡£¡£¡£
CVE-2020-3495Îó²îÓÉWatchcomµÄÇå¾²Ñо¿Ö°Ô±Olav Sortland Thoresen·¢Ã÷²¢±¨¸æ£¬£¬£¬£¬Ë¼¿Æ²úÆ·Çå¾²ÊÂÎñÏìÓ¦ÍŶӣ¨PSIRT£©ÌåÏÖ¸ÃÎó²îÄ¿½ñÉÐδ±»ÆÕ±éʹÓᣡ£¡£
0x01 Îó²îÏêÇé
Cisco Jabber for WindowsÊÇÒ»¿î×ÀÃæÐ×÷Ó¦ÓóÌÐò£¬£¬£¬£¬Ö÷ҪΪÓû§Ìṩ״̬¡¢¼´Ê±ÐÂÎÅ£¨IM£©¡¢ÐÂÎÅ¡¢×ÀÃæ¹²Ïí¡¢ÊÓÆµÒôƵ¾Û»áºÍWeb¾Û»áЧÀÍ¡£¡£¡£
CVE-2020-3495ÊÇÓÉÓÚÓʼþÄÚÈÝÑéÖ¤²»×¼È·ÒýÆðµÄ¡£¡£¡£¹¥»÷Õßͨ¹ýʹÓöñÒâµÄ¿ÉÀ©Õ¹ÐÂÎźÍ״̬ÐÒ飨XMPP£©ÐÂÎÅÀ´Ê¹ÓôËÎó²î£¬£¬£¬£¬Í¨¹ýÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔÔÚδ´ò²¹¶¡µÄ Cisco Jabber for Windows µÄϵͳÉÏÖ´ÐжñÒâ´úÂë¡£¡£¡£²¢ÇÒ£¬£¬£¬£¬¸ÃÎó²îµÄʹÓò»ÐèÒªÓû§½»»¥£¬£¬£¬£¬µ±Jabber for Windows¿Í»§¶ËÔÚºǫ́ÔËÐÐʱ¸ÃÎó²îÒ²¿É±»Ê¹Óᣡ£¡£
µ«ÈôÊÇҪʹÓôËÎó²î£¬£¬£¬£¬¹¥»÷Õß±ØÐèÄܹ»ÏòÔËÐÐWindowsµÄCisco JabberµÄ×îÖÕÓû§ÏµÍ³·¢ËÍXMPPÐÂÎÅ¡£¡£¡£ÈôÀÖ³ÉʹÓôËÎó²î£¬£¬£¬£¬»áµ¼ÖÂÓ¦ÓóÌÐòÔËÐеÄÍâµØÎļþ·¾¶Öб»ÉÏ´«í§ÒâÖ´ÐÐÎļþ£¬£¬£¬£¬¸Ã¿ÉÖ´ÐÐÎļþ½«»áÒÔÆô¶¯Jabber¿Í»§¶ËÓ¦ÓóÌÐòµÄÓû§µÄÌØÈ¨ÔÚÓû§ÏµÍ³ÉÏÔËÐС£¡£¡£
µ«½öÔÚphone-only modeģʽÏÂʹÓÃJabber²¢ÇÒûÓÐÆôÓÃXMPPÐÂÎÅЧÀÍʱϵͳ²»Ò×Êܵ½¹¥»÷£¬£¬£¬£¬µ±JabberÉèÖÃΪʹÓóýXMPPÐÂÎÅת´ïÒÔÍâµÄÐÂÎÅת´ïЧÀÍʱ£¬£¬£¬£¬¸ÃÎó²îÔòÎÞ·¨±»Ê¹Óᣡ£¡£
0x02 ´¦Öóͷ£½¨Òé
½¨ÒéÉý¼¶µ½Êʵ±µÄ°æ±¾£º
ÊÜÓ°Ïì°æ±¾ | ¸üа汾 |
12.1 | 12.1.3 |
12.5 | 12.5.2 |
12.6 | 12.6.3 |
12.7 | 12.7.2 |
12.8 | 12.8.3 |
12.9 | 12.9.1 |
ÏÂÔØµØµã£º
https://software.cisco.com/download/home/284324806/type/284006014/release/12.6(3)
0x03 Ïà¹ØÐÂÎÅ
https://www.bleepingcomputer.com/news/security/cisco-fixes-critical-code-execution-bug-in-jabber-for-windows/
https://securityaffairs.co/wordpress/107834/security/cisco-jabber-for-windows-flaw.html
0x04 ²Î¿¼Á´½Ó
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-jabber-UyTKCPGg
0x05 ʱ¼äÏß
2020-09-02 CiscoÐû²¼Ç徲ͨ¸æ
2020-09-03 VSRCÐû²¼Ç徲ͨ¸æ