Network Security Internet Technology Development Database Servers Mobile Phone Android Software Apple Software Computer Software News IT Information

In addition to Weibo, there is also WeChat

Please pay attention

WeChat public account

Shulou

Unable to fully fix 117 vulnerabilities, Microsoft Microsoft 365temporarily disabled SketchUp tool

2025-02-04 Update From: SLTechnology News&Howtos shulou NAV: SLTechnology News&Howtos > IT Information >

Share

Shulou(Shulou.com)11/24 Report--

CTOnews.com, November 8 (Xinhua)-- Zscaler, a network security company, recently discovered 117 vulnerabilities in the Microsoft suite, all of which exist in SketchUp.

Microsoft then released the corresponding fix, but after testing, the researchers found that it was still possible to bypass the fix and carry out the corresponding attack. For this reason, Microsoft temporarily disabled SketchUp in Microsoft 365 until a better fix was released before opening SketchUp.

CTOnews.com Note: SketchUp is a set of design tools directly oriented to the design scheme creation process, which can not only fully express the designer's ideas, but also fully meet the needs of immediate communication with clients. It enables designers to directly carry out very intuitive ideas on the computer, and is an excellent tool for three-dimensional architectural design scheme creation.

The Zscaler ThreatLabz team revealed that after reverse engineering Office 3D components, they found that Microsoft called multiple SketchUp C API to let the application process SketchUp (SKP) files.

The team discovered more than 20 vulnerabilities in the process, followed by another 97, involving out-of-bounds writes (out-of-bounds write), stack buffer overflow, and so on.

Welcome to subscribe "Shulou Technology Information " to get latest news, interesting things and hot topics in the IT industry, and controls the hottest and latest Internet news, technology news and IT industry trends.

Views: 214

*The comments in the above article only represent the author's personal views and do not represent the views and positions of this website. If you have more insights, please feel free to contribute and share.

Share To

IT Information

Wechat

© 2024 shulou.com SLNews company. All rights reserved.

12
Report