CVE-2017-8555, CVE-2017-9606
[º¸¾È´º½º ¹®°¡¿ë ±âÀÚ] ÇöÁö ½Ã°¢À¸·Î 6¿ù 14ÀÏ, ¿ì¸®³ª¶ó ½Ã°£À¸·Î´Â ´ë·« 14ÀÏ¿¡¼ 15ÀÏ·Î ³Ñ¾î¿À´Â ¹ã »çÀÌ¿¡ ¹Ì±¹ÀÇ National Vulnerability DatabaseÀ» ÅëÇØ ¹ßÇ¥µÈ Ãë¾àÁ¡µéÀÌ´Ù.
1. CVE-2017-8551
Microsoft SharePoint ¼ÒÇÁÆ®¿þ¾îÀÇ ±ÇÇÑ »ó½Â Ãë¾àÁ¡À¸·Î Á¶ÀÛµÈ ¿äûÀ» Á¦´ë·Î °É·¯³»Áö ¸øÇÏ°Ô ÇÑ´Ù. Microsoft SharePoint XSS Ãë¾àÁ¡À̶ó°íµµ ¾Ë·ÁÁ® ÀÖ´Ù.
2. CVE-2017-8552
Windows Server 2008 SP2¿Í R2 SP1, Windows 7 SP1ÀÇ Ä¿³Î ¸ðµå µå¶óÀ̹öÀÇ ±ÇÇÑ »ó½Â Ãë¾àÁ¡À¸·Î ¸Þ¸ð¸® ³» °´Ã¼µéÀ» Á¦´ë·Î ó¸®ÇÏÁö ¸øÇÑ´Ù. Win32k Elevation of Privilege Vulnerability¶ó°íµµ ¾Ë·ÁÁ® ÀÖ´Ù. CVE-2017-0263°ú º°°³ÀÇ Ãë¾àÁ¡ÀÌ´Ù.
3. CVE-2017-8553
Windows Server 2008 SP2¿Í R2 SP1, Windows 8.1, Windows Server 2012 Gold¿Í R2, Windows RT 8.1, Windows Server 2016ÀÇ Á¤º¸ ³ëÃâ Ãë¾àÁ¡À¸·Î À©µµ¿ì Ä¿³ÎÀÌ ¸Þ¸ð¸® ³» °´Ã¼µéÀ» Á¦´ë·Î ó¸®ÇÏÁö ¸øÇØ ¹ß»ýÇÑ´Ù. GDI Information Disclosure Vulnerability¶ó°íµµ ¾Ë·ÁÁ® ÀÖ´Ù.
4. CVE-2017-8555
Microsoft Windows 10 1703ÀÇ Microsoft EdgeÀÇ Edge Content Security PolicyÀÇ Ãë¾àÁ¡À¸·Î °ø°ÝÀÚ°¡ »ç¿ëÀÚ¸¦ ¼Ó¿© ¾Ç¼º ÄÜÅÙÃ÷°¡ Æ÷ÇԵǾî ÀÖ´Â ÆäÀÌÁö¸¦ ·ÎµùÇϵµ·Ï ¸¸µç´Ù. Microsoft Edge Security Feature Bypass Vulnerability¶ó°íµµ ¾Ë·ÁÁ® ÀÖ´Ù. CVE-2017-8523°ú CVE-2017-8530°ú´Â ´Ù¸¥ Ãë¾àÁ¡ÀÌ´Ù.
5. CVE-2017-9606
Infotecs ViPNet Client¿Í Coordinator 4.3.2-42442 ÀÌÀü ¹öÀüÀÇ Ãë¾àÁ¡À¸·Î ·ÎÄÃÀÇ »ç¿ëÀÚ°¡ ³ôÀº ±ÇÇÑÀ» ÃëµæÇÒ ¼ö ÀÖµµ·Ï ÇØÁØ´Ù. Æú´õ ÆÛ¹Ì¼Ç ¹æ½ÄÀÇ ¿À·ù·ÎºÎÅÍ ¹ß»ýÇÏ´Â Ãë¾àÁ¡ÀÌ´Ù.
[±¹Á¦ºÎ ¹®°¡¿ë ±âÀÚ(globoan@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(www.boannews.com) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>