CVE-2020-3495 | Cisco JabberÔ¶³Ì´úÂëÖ´ÐÐÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-09-03

0x00 Îó²î¸ÅÊö

CVE   ID

CVE-2020-3495

ʱ    ¼ä

2020-09-03

Àà    ÐÍ

RCE

µÈ    ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

ËùÓÐÊÊÓÃWindows Cisco Jabber¿Í»§¶Ë°æ±¾£¨12.1ÖÁ12.9£©

 

2020Äê09ÔÂ02ÈÕ £¬£¬ £¬£¬Cisco¹Ù·½ÐÞ¸´ÁËÒ»¸öÑÏÖØµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-3495£© £¬£¬ £¬£¬¸ÃÎó²îCVSSÆÀ·ÖΪ9.9·Ö¡£¡£¡£

CVE-2020-3495Îó²îÓÉWatchcomµÄÇå¾²Ñо¿Ö°Ô±Olav Sortland Thoresen·¢Ã÷²¢±¨¸æ £¬£¬ £¬£¬Ë¼¿Æ²úÆ·Çå¾²ÊÂÎñÏìÓ¦ÍŶӣ¨PSIRT£©ÌåÏÖ¸ÃÎó²îÄ¿½ñÉÐδ±»ÆÕ±éʹÓᣡ£¡£

0x01 Îó²îÏêÇé

 

ͼƬ4.png


 

Cisco Jabber for WindowsÊÇÒ»¿î×ÀÃæÐ­×÷Ó¦ÓóÌÐò £¬£¬ £¬£¬Ö÷ҪΪÓû§Ìṩ״̬¡¢¼´Ê±ÐÂÎÅ£¨IM£©¡¢ÐÂÎÅ¡¢×ÀÃæ¹²Ïí¡¢ÊÓÆµÒôƵ¾Û»áºÍWeb¾Û»áЧÀÍ¡£¡£¡£

CVE-2020-3495ÊÇÓÉÓÚÓʼþÄÚÈÝÑéÖ¤²»×¼È·ÒýÆðµÄ¡£¡£¡£¹¥»÷Õßͨ¹ýʹÓöñÒâµÄ¿ÉÀ©Õ¹ÐÂÎźÍ״̬ЭÒ飨XMPP£©ÐÂÎÅÀ´Ê¹ÓôËÎó²î £¬£¬ £¬£¬Í¨¹ýÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔÔÚδ´ò²¹¶¡µÄ Cisco Jabber for Windows µÄϵͳÉÏÖ´ÐжñÒâ´úÂë¡£¡£¡£²¢ÇÒ £¬£¬ £¬£¬¸ÃÎó²îµÄʹÓò»ÐèÒªÓû§½»»¥ £¬£¬ £¬£¬µ±Jabber for Windows¿Í»§¶ËÔÚºǫ́ÔËÐÐʱ¸ÃÎó²îÒ²¿É±»Ê¹Óᣡ£¡£

µ«ÈôÊÇҪʹÓôËÎó²î £¬£¬ £¬£¬¹¥»÷Õß±ØÐèÄܹ»ÏòÔËÐÐWindowsµÄCisco JabberµÄ×îÖÕÓû§ÏµÍ³·¢ËÍXMPPÐÂÎÅ¡£¡£¡£ÈôÀÖ³ÉʹÓôËÎó²î £¬£¬ £¬£¬»áµ¼ÖÂÓ¦ÓóÌÐòÔËÐеÄÍâµØÎļþ·¾¶Öб»ÉÏ´«í§ÒâÖ´ÐÐÎļþ £¬£¬ £¬£¬¸Ã¿ÉÖ´ÐÐÎļþ½«»áÒÔÆô¶¯Jabber¿Í»§¶ËÓ¦ÓóÌÐòµÄÓû§µÄÌØÈ¨ÔÚÓû§ÏµÍ³ÉÏÔËÐС£¡£¡£

µ«½öÔÚphone-only modeģʽÏÂʹÓÃJabber²¢ÇÒûÓÐÆôÓÃXMPPÐÂÎÅЧÀÍʱϵͳ²»Ò×Êܵ½¹¥»÷ £¬£¬ £¬£¬µ±JabberÉèÖÃΪʹÓóýXMPPÐÂÎÅת´ïÒÔÍâµÄÐÂÎÅת´ïЧÀÍʱ £¬£¬ £¬£¬¸ÃÎó²îÔòÎÞ·¨±»Ê¹Óᣡ£¡£

0x02 ´¦Öóͷ£½¨Òé

½¨ÒéÉý¼¶µ½Êʵ±µÄ°æ±¾£º

ÊÜÓ°Ïì°æ±¾

¸üа汾

12.1

12.1.3

12.5

12.5.2

12.6

12.6.3

12.7

12.7.2

12.8

12.8.3

12.9

12.9.1

ÏÂÔØµØµã£º

https://software.cisco.com/download/home/284324806/type/284006014/release/12.6(3)

 

0x03 Ïà¹ØÐÂÎÅ

https://www.bleepingcomputer.com/news/security/cisco-fixes-critical-code-execution-bug-in-jabber-for-windows/

https://securityaffairs.co/wordpress/107834/security/cisco-jabber-for-windows-flaw.html

 

0x04 ²Î¿¼Á´½Ó

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-jabber-UyTKCPGg

0x05 ʱ¼äÏß

2020-09-02 CiscoÐû²¼Ç徲ͨ¸æ

2020-09-03 VSRCÐû²¼Ç徲ͨ¸æ



ͼƬ5.png