΢ÈíAndroid°æOutlook XSSÎó²î

Ðû²¼Ê±¼ä 2019-06-22


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


Åä¾°ÐÎò


΢ÈíÐû²¼Android°æOutlookÇå¾²¸üР£¬ÐÞ¸´Ò»¸ö´æ´¢ÐÍXSSÎó²î£¨CVE-2019-1105 £©¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢ËͶñÒâµç×ÓÓʼþ´¥·¢¸ÃÎó²î £¬´Ó¶øÔÚÄ¿µÄ×°±¸ÉÏÖ´ÐжñÒâµÄÓ¦ÓÃÄÚ¿Í»§¶Ë´úÂë¡£


Îó²îÁбí


CVE ID  £º   CVE-2019-1105
Îó²îÆ·¼¶£º   ÖÐΣ
CVSSÆÀ·Ö£º   ÔÝÎÞ
Ó°Ïì¹æÄ££º   Outlook for Android 3.0.88֮ǰµÄ°æ±¾

Îó²îÏêÇé


ƾ֤΢ÈíÐû²¼µÄÇ徲ͨ¸æ £¬Outlook for Android 3.0.88֮ǰµÄ°æ±¾±£´æÒ»¸ö´æ´¢ÐÍXSSÎó²î£¨CVE-2019-1105£©¡£¸ÃÎó²îÓëAPPÆÊÎö´«Èëµç×ÓÓʼþµÄ·½·¨ÓÐ¹Ø £¬¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿Éͨ¹ýÏòÄ¿µÄ·¢ËͶñÒâµç×ÓÓʼþÀ´Ê¹ÓôËÎó²î¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÄÜ»á¶ÔÊÜÓ°ÏìµÄϵͳִÐпçÕ¾¾ç±¾¹¥»÷ £¬²¢ÔÚÄ¿½ñÓû§µÄÇå¾²ÉÏÏÂÎÄÖÐÔËÐо籾¡£´ËÇå¾²¸üÐÂͨ¹ý¸üÕýOutlook for AndroidÆÊÎöÌØ¶¨µç×ÓÓʼþµÄ·½·¨À´ÐÞ¸´¸ÃÎó²î¡£


΢Èí³Æ¸ÃÎó²îÊÇÓɶà¸öÇå¾²Ñо¿Ö°Ô±×ÔÁ¦±¨¸æµÄ £¬²¢ÇÒ¿ÉÄܻᵼÖÂÓÕÆ­ÀàÐ͵Ĺ¥»÷¡£´ËÎó²îµÄÏêϸÊÖÒÕϸ½Ú»ò¿´·¨ÑéÖ¤ÉÐδ¹ûÕæÐû²¼¡£ÏÖÔÚ΢ÈíÉÐδ·¢Ã÷Óë´ËÎó²îÓйصÄÈκι¥»÷ÊÂÎñ¡£

ÐÞ¸´½¨Òé


ÈôÊÇÓû§µÄAndroid×°±¸ÉÐδ×Ô¶¯¸üР£¬½¨ÒéÓû§´ÓGoogle PlayÊÐËÁÊÖ¶¯¸üÐÂOutlook APP¡£

²Î¿¼Á´½Ó


https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1105
https://thehackernews.com/2019/06/outlook-app-android.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1105