ANA事件單通知【漏洞預警】微軟Outlook存在權限擴張之高風險安全漏洞,允許遠端攻擊者取得受駭者身分鑑別雜湊值,進而執行偽冒身分攻擊,請儘速確認並採取緩解措施!
教育機構ANA通報平台
| 發佈編號 | 發佈時間 | ||
| 事故類型 | ANA-漏洞預警 | 發現時間 | 2023-04-07 11:12:48 |
| 影響等級 | 低 | ||
| [主旨說明:]【漏洞預警】 |
|||
[內容說明:]
轉發 國家資安資訊分享與分析中心 NISAC-ANA-202304-0215 研究人員發現微軟Outlook存在權限擴張( |
|||
[影響平台:]
● Microsoft 365 Apps for Enterprise for 32-bit Systems ● Microsoft 365 Apps for Enterprise for 64-bit Systems ● Microsoft Office 2019 for 32-bit editions ● Microsoft Office 2019 for 64-bit editions ● Microsoft Office LTSC 2021 for 32-bit editions ● Microsoft Office LTSC 2021 for 64-bit editions ● Microsoft Outlook 2013 RT Service Pack 1 ● Microsoft Outlook 2013 Service Pack 1(32-bit editions) ● Microsoft Outlook 2013 Service Pack 1(64-bit editions) ● Microsoft Outlook 2016(32-bit edition) ● Microsoft Outlook 2016(64-bit edition) |
|||
[建議措施:]
目前微軟官方已針對弱點釋出修復版本, |
|||
| [參考資料:] 1. https://www.microsoft.com/en- 2. https://www.ithome.com.tw/ 3. https://www.xmcyber.com/blog/ 4. https://msrc.microsoft.com/ 5. https://www. |
|||
