:::

【資安漏洞預警】一等一科技|U-Office Force - Insecure Deserialization
[Security Vulnerability Alert] e-Excellence | U-Office Force - Insecure Deserialization

公告類別:行政公告
發佈日期:2026/03/11 至 2026/09/11
點閱數:261

轉發 台灣電腦網路危機處理暨協調中心 資安訊息警訊 TWCERTCC-200-202603-00000003

[內容說明]
【一等一科技|U-Office Force - Insecure Deserialization】(CVE-2026-3422,CVSS:98) 一等一科技開發之U-Office Force存在Insecure Deserialization漏洞,未經身分鑑別之遠端攻擊者可透過發送惡意序列化內容於伺服器端執行任意程式碼。

[影響平台]
U-Office Force 29.50(含)以前版本

[建議措施]
請更新至29.50SP1(含)之後版本

[參考資料]
1. https://www.twcert.org.tw/tw/cp-132-10742-45b13-1.html
Forwarded from Taiwan Computer Network Crisis Management and Coordination Center: Cybersecurity Alert TWCERTCC-200-202603-00000003

[Content Description]
【e-Excellence|U-Office Force - Insecure Deserialization】(CVE-2026-3422, CVSS: 98) e-Excellence U-Office Force contains an Insecure Deserialization vulnerability. An unauthenticated remote attacker can execute arbitrary code on the server by sending malicious serialized content.

[Affected Platforms]
U-Office Force versions 29.50 and earlier

[Recommended Action]
Please update to version 29.50SP1 or later.

[References]
1. https://www.twcert.org.tw/tw/cp-132-10742-45b13-1.html

相關附件

返回列表