{"id":4551,"date":"2023-10-16T13:02:28","date_gmt":"2023-10-16T05:02:28","guid":{"rendered":"https:\/\/aict.nkust.edu.tw\/digitrans\/?p=4551"},"modified":"2023-10-20T13:06:06","modified_gmt":"2023-10-20T05:06:06","slug":"microsoft-%e7%b7%8a%e6%80%a5%e6%8e%a8%e5%87%ba-edge%e3%80%81teams-%e6%9b%b4%e6%96%b0%ef%bc%8c%e4%bf%ae%e5%be%a9-2-%e5%80%8b%e9%96%8b%e6%ba%90%e7%b5%84%e4%bb%b6%e4%b8%ad%e7%9a%84-0-day-%e6%bc%8f","status":"publish","type":"post","link":"https:\/\/aict.nkust.edu.tw\/digitrans\/?p=4551","title":{"rendered":"Microsoft \u7dca\u6025\u63a8\u51fa Edge\u3001Teams \u66f4\u65b0\uff0c\u4fee\u5fa9 2 \u500b\u958b\u6e90\u7d44\u4ef6\u4e2d\u7684 0-day \u6f0f\u6d1e"},"content":{"rendered":"\n<p>\u767c\u5e03\u55ae\u4f4d:TWCERT\/CC \u66f4\u65b0\u65e5\u671f:2023-10-16<\/p>\n\n\n\n<p>Microsoft \u65e5\u524d\u7dca\u6025\u91dd\u5c0d\u65d7\u4e0b\u7684 Microsoft Edge\u3001Teams \u8207 Skype \u7dca\u6025\u63a8\u51fa\u8edf\u9ad4\u66f4\u65b0\uff0c\u4fee\u5fa9 2 \u500b\u5b58\u65bc\u958b\u6e90\u7a0b\u5f0f\u5eab\u4e2d\u7684 0-day \u6f0f\u6d1e\u3002<\/p>\n\n\n\n<p>\u7b2c\u4e00\u500b\u7372\u5f97\u4fee\u5fa9\u7684\u6f0f\u6d1e\u662f CVE-2023-4863\uff0c\u9019\u500b\u6f0f\u6d1e\u5b58\u65bc\u958b\u6e90 WebP \u7a0b\u5f0f\u5eab libwebp \u4e2d\uff0c\u5c6c\u65bc heap \u7de9\u885d\u5340\u6ea2\u4f4d\uff08buffer overflow\uff09\u932f\u8aa4\uff1b\u99ed\u4fb5\u8005\u53ef\u900f\u904e\u6b64\u6f0f\u6d1e\u9020\u6210\u61c9\u7528\u8edf\u9ad4\u5d29\u6f70\uff0c\u4ea6\u53ef\u57f7\u884c\u4efb\u610f\u7a0b\u5f0f\u78bc\u3002<\/p>\n\n\n\n<p>\u503c\u5f97\u6ce8\u610f\u7684\u662f\uff0c\u7531\u65bc libwebp \u9019\u500b\u958b\u6e90\u7a0b\u5f0f\u5eab\u662f\u7528\u4f86\u5c0d WebP \u683c\u5f0f\u7684\u7db2\u8def\u5716\u7247\u9032\u884c\u7de8\u78bc\u8207\u89e3\u78bc\uff0c\u56e0\u6b64\u61c9\u7528\u7bc4\u570d\u5341\u5206\u5ee3\u6cdb\uff1b\u9664\u4e86 Microsoft \u9019\u6b21\u4fee\u5fa9\u7684\u4e09\u500b\u7522\u54c1\u5916\uff0c\u5305\u62ec Safari\u3001Mozilla Firefox\u3001Opera\u3001Android \u539f\u751f\u700f\u89bd\u5668\u4e4b\u5916\uff0c\u50cf\u662f 1Password \u8207 Signal \u7b49\u71b1\u9580\u61c9\u7528\u8edf\u9ad4\u4e5f\u63a1\u7528\u4e86 libwebp\uff0c\u56e0\u6b64\u90fd\u9700\u9032\u884c\u8cc7\u5b89\u4fee\u88dc\u3002<\/p>\n\n\n\n<p>\u7b2c\u4e8c\u500b\u7372\u5f97\u4fee\u5fa9\u7684\u6f0f\u6d1e\u662f CVE-2023-5217\uff0c\u9019\u500b\u6f0f\u6d1e\u5b58\u65bc\u958b\u6e90 VP8 \u7a0b\u5f0f\u5eab libvpx \u4e2d\u7684\u8996\u8a0a\u7de8\u78bc\u7a0b\u5f0f\uff0c\u548c\u524d\u4e00\u500b\u6f0f\u6d1e\u4e00\u6a23\u5c6c\u65bc heap \u7de9\u885d\u5340\u6ea2\u4f4d\uff08buffer overflow\uff09\u932f\u8aa4\uff1b\u99ed\u4fb5\u8005\u4e5f\u53ef\u900f\u904e\u6b64\u6f0f\u6d1e\u9020\u6210\u61c9\u7528\u8edf\u9ad4\u5d29\u6f70\uff0c\u4ea6\u53ef\u57f7\u884c\u4efb\u610f\u7a0b\u5f0f\u78bc\u3002<\/p>\n\n\n\n<p>\u800c libvpx \u9019\u500b\u958b\u6e90\u7a0b\u5f0f\u5eab\uff0c\u56e0\u70ba\u8ca0\u8cac\u8655\u7406 VP8 \u548c VP9 \u5169\u7a2e\u5f71\u7247\u683c\u5f0f\u7684\u7de8\u89e3\u78bc\uff0c\u56e0\u6b64 \u540c\u6a23\u5ee3\u6cdb\u61c9\u7528\u5728\u591a\u7a2e\u8edf\u9ad4\u4e4b\u4e2d\uff0c\u5305\u62ec\u591a\u7a2e\u5f71\u97f3\u4e32\u6d41\u5e73\u53f0\u7684 App \u5982 Netflix\u3001YouTube\u3001Amazon Prime Video \u7b49\u4e5f\u90fd\u4f7f\u7528\u3002<\/p>\n\n\n\n<p>\u76ee\u524d\u5df2\u77e5\u6709\u99ed\u4fb5\u8005\u5229\u7528\u9019\u5169\u500b\u5f71\u97ff\u5ee3\u6cdb\u7684\u6f0f\u6d1e\uff0c\u4f86\u767c\u52d5\u9593\u8adc\u8edf\u9ad4\u653b\u64ca\uff0c\u4f7f\u7528\u8005\u61c9\u7279\u5225\u63d0\u9ad8\u8b66\u89ba\u3002<\/p>\n\n\n\n<p>\u5efa\u8b70\u4f7f\u7528 Microsoft \u4ee5\u4e0a\u7522\u54c1\u7684\u4f7f\u7528\u8005\uff0c\u61c9\u5118\u901f\u5957\u7528\u66f4\u65b0\uff0c\u4ee5\u514d\u906d\u5230\u99ed\u4fb5\u8005\u900f\u904e\u5df2\u77e5\u6f0f\u6d1e\u767c\u52d5\u653b\u64ca\u3002<\/p>\n\n\n\n<p>\u8cc7\u6599\u4f86\u6e90\uff1a<a href=\"https:\/\/www.twcert.org.tw\/tw\/cp-104-7456-09bf3-1.html\" data-type=\"link\" data-id=\"https:\/\/www.twcert.org.tw\/tw\/cp-104-7456-09bf3-1.html\">https:\/\/www.twcert.org.tw\/tw\/cp-104-7456-09bf3-1.html<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u767c\u5e03\u55ae\u4f4d:TWCERT\/CC \u66f4\u65b0\u65e5\u671f:2023-10-16 Microsoft \u65e5\u524d\u7dca\u6025\u91dd\u5c0d\u65d7\u4e0b\u7684 Microsoft Edge\u3001Teams \u8207 Skype \u7dca\u6025\u63a8\u51fa\u8edf\u9ad4\u66f4\u65b0\uff0c\u4fee&hellip;<\/p>\n","protected":false},"author":9,"featured_media":4552,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[352],"tags":[204],"class_list":["post-4551","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-information-security","tag-204"],"gutentor_comment":0,"jetpack_featured_media_url":"https:\/\/i0.wp.com\/aict.nkust.edu.tw\/digitrans\/wp-content\/uploads\/2023\/10\/6602310161741c128a-e1697778350716.png?fit=903%2C676&ssl=1","jetpack-related-posts":[],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/posts\/4551","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4551"}],"version-history":[{"count":1,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/posts\/4551\/revisions"}],"predecessor-version":[{"id":4553,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/posts\/4551\/revisions\/4553"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/media\/4552"}],"wp:attachment":[{"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4551"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4551"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4551"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}