Bleeping Computer¤Ï7·î11Æü(Êƹñ»þ´Ö)¡¢¡ÖMicrosoft: Unpatched Office zero-day exploited in NATO summit attacks¡×¤Ë¤ª¤¤¤Æ¡¢Ê£¿ô¤ÎWindows¤ª¤è¤ÓMicrosoft OfficeÀ½Éʤ˥ѥåÁ¤¬Å¬ÍѤµ¤ì¤Æ¤¤¤Ê¤¤¥¼¥í¥Ç¥¤ÀȼåÀ­¤¬¤¢¤ë¤ÈÅÁ¤¨¤¿¡£¤³¤ÎÀȼåÀ­¤¬°­ÍѤµ¤ì¤¿¾ì¹ç¡¢¹¶·â¼Ô¤Ë¤è¤Ã¤Æµ¡Ì©¾ðÊó¤Ë¥¢¥¯¥»¥¹¤µ¤ì¤¿¤ê¡¢¥·¥¹¥Æ¥àÊݸî¤ò̵¸ú²½¤µ¤ì¤¿¤ê¡¢¿¯³²¤µ¤ì¤¿¥·¥¹¥Æ¥à¤Ø¥¢¥¯¥»¥¹¤Ç¤­¤Ê¤¯¤Ê¤Ã¤¿¤ê¤¹¤ë²ÄǽÀ­¤¬¤¢¤ë¡£

Microsoft: Unpatched Office zero-day exploited in NATO summit attacks

¡ÖCVE-2023-36884¡×¤È¤·¤ÆÄÉÀפµ¤ì¤Æ¤¤¤ë̤½¤Àµ¤ÎÀȼåÀ­¤¬Êó¹ð¤µ¤ì¤¿¡£¥ê¥â¡¼¥È¥³¡¼¥É¼Â¹Ô(RCE: Remote Code Execution)¤ÎÀȼåÀ­¤Ç¡¢¶¦ÄÌÀȼåÀ­É¾²Á¥·¥¹¥Æ¥à(CVSS: Common Vulnerability Scoring System)¤Î¥¹¥³¥¢Ãͤ¬8.3¤ÈʬÎव¤ì¡¢¿¼¹ïÅÙ¤¬½ÅÂç(Important)¤È°ÌÃ֤Ť±¤é¤ì¤Æ¤¤¤ë¡£

Microsoft¤Ï¤³¤ÎÀȼåÀ­¤Ë¤Ä¤¤¤ÆÄ´ºº¤ò¹Ô¤Ã¤Æ¤ª¤ê¡¢¹¶·â¼Ô¤¬ÆÃÊ̤˺îÀ®¤µ¤ì¤¿Microsoft Office¥É¥­¥å¥á¥ó¥È¤È¤³¤Î·ç´Ù¤ò°­ÍѤ·¤ÆɸŪ·¿¹¶·â¤ò¹Ô¤Ã¤Æ¤¤¤ë¤ÈÊó¹ð¤·¤Æ¤¤¤ë¡£¤¿¤À¤·¤³¤Î¹¶·â¤Ï¡¢¥Õ¥£¥Ã¥·¥ó¥°¹¶·â¤Ê¤É¤ò»È¤Ã¤ÆÈï³²¼Ô¤Ë°­°Õ¤Î¤¢¤ë¥Õ¥¡¥¤¥ë¤ò³«¤«¤»¤ëɬÍפ¬¤¢¤ë¤È¤Î¤³¤È¤À¡£

Microsoft¤ÏÄ´ºº¤¬´°Î»¤·¤Æ¤«¤é·îÎã¥ê¥ê¡¼¥¹¥×¥í¥»¥¹¤Þ¤¿¤ÏÎ×»þ¤Î¥»¥­¥å¥ê¥Æ¥£¥¢¥Ã¥×¥Ç¡¼¥È¤òÄ󶡤¹¤ë¤È½Ò¤Ù¤Æ¤¤¤ë¡£¤Þ¤¿¡¢CVE-2023-36884¤Ë¥Ñ¥Ã¥Á¤¬Ä󶡤µ¤ì¤ë¤Þ¤Ç¤Î´ËϺö¤âÄ󶡤·¤Æ¤¤¤ë¡£Windows¤ª¤è¤ÓOffice¥æ¡¼¥¶¡¼¤ÏÅŻҥ᡼¥ë¤ÎźÉÕ¥Õ¥¡¥¤¥ë¤ä¥ê¥ó¥¯¤ËÃí°Õ¤òʧ¤¦¤È¤È¤â¤Ë¡¢Microsoft¤¬¿ä¾©¤·¤Æ¤¤¤ë´ËϺö¤ò¼Â»Ü¤¹¤ë¤³¤È¤¬Ë¾¤Þ¤ì¤Æ¤¤¤ë¡£