΢ÈíAndroid°æOutlook XSSÎó²î

Ðû²¼Ê±¼ä 2019-06-22


Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾


Åä¾°ÐÎò


΢ÈíÐû²¼Android°æOutlookÇå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´Ò»¸ö´æ´¢ÐÍXSSÎó²î£¨CVE-2019-1105 £©¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢ËͶñÒâµç×ÓÓʼþ´¥·¢¸ÃÎó²î£¬£¬£¬£¬£¬£¬´Ó¶øÔÚÄ¿µÄ×°±¸ÉÏÖ´ÐжñÒâµÄÓ¦ÓÃÄÚ¿Í»§¶Ë´úÂë¡£¡£¡£¡£¡£


Îó²îÁбí


CVE ID  £º   CVE-2019-1105
Îó²îÆ·¼¶£º   ÖÐΣ
CVSSÆÀ·Ö£º   ÔÝÎÞ
Ó°Ïì¹æÄ££º   Outlook for Android 3.0.88֮ǰµÄ°æ±¾

Îó²îÏêÇé


ƾ֤΢ÈíÐû²¼µÄÇ徲ͨ¸æ£¬£¬£¬£¬£¬£¬Outlook for Android 3.0.88֮ǰµÄ°æ±¾±£´æÒ»¸ö´æ´¢ÐÍXSSÎó²î£¨CVE-2019-1105£©¡£¡£¡£¡£¡£¸ÃÎó²îÓëAPPÆÊÎö´«Èëµç×ÓÓʼþµÄ·½·¨ÓйØ£¬£¬£¬£¬£¬£¬¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿Éͨ¹ýÏòÄ¿µÄ·¢ËͶñÒâµç×ÓÓʼþÀ´Ê¹ÓôËÎó²î¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÄÜ»á¶ÔÊÜÓ°ÏìµÄϵͳִÐпçÕ¾¾ç±¾¹¥»÷£¬£¬£¬£¬£¬£¬²¢ÔÚÄ¿½ñÓû§µÄÇå¾²ÉÏÏÂÎÄÖÐÔËÐо籾¡£¡£¡£¡£¡£´ËÇå¾²¸üÐÂͨ¹ý¸üÕýOutlook for AndroidÆÊÎöÌØ¶¨µç×ÓÓʼþµÄ·½·¨À´ÐÞ¸´¸ÃÎó²î¡£¡£¡£¡£¡£


΢Èí³Æ¸ÃÎó²îÊÇÓɶà¸öÇå¾²Ñо¿Ö°Ô±×ÔÁ¦±¨¸æµÄ£¬£¬£¬£¬£¬£¬²¢ÇÒ¿ÉÄܻᵼÖÂÓÕÆ­ÀàÐ͵Ĺ¥»÷¡£¡£¡£¡£¡£´ËÎó²îµÄÏêϸÊÖÒÕϸ½Ú»ò¿´·¨ÑéÖ¤ÉÐδ¹ûÕæÐû²¼¡£¡£¡£¡£¡£ÏÖÔÚ΢ÈíÉÐδ·¢Ã÷Óë´ËÎó²îÓйصÄÈκι¥»÷ÊÂÎñ¡£¡£¡£¡£¡£

ÐÞ¸´½¨Òé


ÈôÊÇÓû§µÄAndroid×°±¸ÉÐδ×Ô¶¯¸üУ¬£¬£¬£¬£¬£¬½¨ÒéÓû§´ÓGoogle PlayÊÐËÁÊÖ¶¯¸üÐÂOutlook APP¡£¡£¡£¡£¡£

²Î¿¼Á´½Ó


https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1105
https://thehackernews.com/2019/06/outlook-app-android.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1105