セキュリティホール memo - 2025.12

Last modified: Mon May 11 17:08:11 2026 +0900 (JST)


 このページの情報を利用される前に、注意書きをお読みください。


■ 2025.12.31


■ 2025.12.25

■ 追記

Apple 方面 (iOS / iPadOS, tvOS, watchOS, visionOS, macOS, Safari) 0-day 対応含む (2025.12.15)

 WebKitGTK and WPE WebKit Security Advisory WSA-2025-0010 (oss-sec ML, 2025.12.17)。 CVE-2025-43529, CVE-2025-14174 の修正が含まれています。

■ いろいろ (2025.12.25)
(various)

Exim

Avahi simple protocol server

Dropbear


■ 2025.12.24


■ 2025.12.23

■ いろいろ (2025.12.23)
(various)

ASRock / ASUS / Gigabyte / MSI マザーボード Pre-Boot DMA Protection 機能

■ 追記

2025 年 12 月のセキュリティ更新プログラム (月例) (2025.12.10)

 トレンドマイクロ Apex One や ビジネスセキュリティ サービス で不具合が発生しているそうで。


■ 2025.12.22

■ WatchGuard製Fireboxのikedにおける境界外書き込みの脆弱性(CVE-2025-14733)に関する注意喚起
(JPCERT/CC, 2025.12.22)

 WatchGuard Firebox の Fireware OS に 0-day 欠陥。 iked に境界外書き込みを許す欠陥があり、remote から無認証で任意のコードを実行できる。

 修正版ファームウェアが用意されているので適用すればよい。 ただし 11.x については EOL で修正版が存在しない。

Vulnerable Version Resolved Version
2025.1 2025.1.4
12.x 12.11.6
12.5.x (T15 & T35 models) 12.5.15
12.3.1 (FIPS-certified release) 12.3.1_Update4 (B728352)
11.x End of Life

 回避策として紹介されているのは (DeepL AI 訳)、

Fireboxが静的ゲートウェイピアへのブランチオフィスVPNトンネルのみに構成されており、脆弱性修正を含むFireware OSバージョンへ直ちにデバイスをアップグレードできない場合、一時的な回避策としてWatchGuardの推奨事項IPSecおよびIKEv2を使用するブランチオフィスVPNへのセキュアアクセスに従うことができます。

 「静的ゲートウェイピアへのブランチオフィスVPNトンネルのみに構成されており」が満足されない場合は、回避策は無い模様。

 https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00027 に注目すべき IP アドレスや注目すべき log エントリーが紹介されているので参照されたい。DeepL AI 訳:

以下のIPアドレスは既知の脅威アクターの活動と直接関連しています。これらのIPへのアウトバウンド接続は侵害の強い指標となります。これらのIPからのインバウンド接続は偵察活動やエクスプロイトの試みを示している可能性があります。

45.95.19[.]50
51.15.17[.]89
172.93.107[.]67
199.247.7[.]82

■ 2025.12.19

■ 追記

Firefox 146.0 / ESR 140.6.0 / ESR 115.31.0 公開 (2025.12.10)

 Firefox 146.0.1、Firefox for Android 146.0.1、 Thunderbird 146.0.1 が公開されている。 Firefox 146.0.1、Firefox for Android 146.0.1 にはセキュリティ修正が含まれる。

2025 年 12 月のセキュリティ更新プログラム (月例) (2025.12.10)

 MSMQ に不具合発生。対応 patch が公開されている。

■ Chrome Stable Channel Update for Desktop
(Google, 2025.12.16)

 Chrome 143.0.7499.146/.147 (Windows / Mac) および 143.0.7499.146 (Linux) 公開。2 件のセキュリティ修正を含む。のだが、コピペがひどい。

2025-12-12: Updated to include more details for bug number 466192044

 これは Chrome 143.0.7499.109/.110 (Windows / Mac) および 143.0.7499.109 (Linux) (Google, 2025.12.10) で修正された個所。

 関連:


■ 2025.12.18


■ 2025.12.17


■ 2025.12.16

■ いろいろ (2025.12.16)
(various)

セイコーエプソン プリンター Web Config

  • プリンターのWeb Configで任意のコマンドが実行可能な脆弱性について (EPSON, 2025.12.16)

    ■対象製品
    レシートプリンター
    TM-H6000V/TM-L100/TM-m10/TM-m30/TM-m30Ⅱ/TM-m30Ⅱ-H/TM-m30Ⅱ-S/TM-m30Ⅱ-SL
    /TM-P60Ⅱ/TM-P20/TM-P80/TM-T20Ⅱ/TM-T20Ⅲ/TM-T88Ⅵ/TM-T88Ⅵ-iHUB/UB-R04(注2)
    /UB-E04
    大判プリンター
    SC-P10050/SC-P20050/SC-P6050/SC-P7050/SC-P8050/SC-P9050/SC-T3250/SC-T3255
    /SC-T5250/SC-T5250D/SC-T5255/SC-T5255D/SC-T7250/SC-T7250D/SC-T7255/SC-T7255D
    ページプリンター
    LP-M8170シリーズ/LP-S180DN/LP-S280DN/LP-S380DN/LP-S3250/LP-S340DN/LP-S3550/LP-S4250
    /LP-S440DN/LP-S6160/LP-S7160/LP-S8160/LP-S9070/LP-S950
    (中略)
    ■対策方法
    現時点でUB-R04以外の製品につきましては対策ファームウエアを公開しています。

    UB-R04 (「無線 LAN 対応 EPSON TM プリンターに搭載されている、無線 LAN インターフェイス」) については対策ファームウエアの公開予定が無いそうで。 管理者パスワードを変更する等の回避策の実施が推奨されている。

    無線LANインターフェイスマニュアル (レシートプリンター / EPSON) によると UB-R04 マニュアル (リビジョン C) は 2014年9月9日公開 であり、かなり古い製品。 サポート終了なのも無理はない。

Universal Boot Loader (U-Boot)

Intel Xeon 6 Processors with P-cores with Intel TDX Connect


■ 2025.12.15

■ Apple 方面 (iOS / iPadOS, tvOS, watchOS, visionOS, macOS, Safari) 0-day 対応含む
(Apple, 2025.12.12)

 0-day は WebKit CVE-2025-43529 CVE-2025-14174 です。iOS < 26 への攻撃が確認されているそうです。 CVE-2025-14174 は Chrome / Edge でも修正が入ってます。

■ 追記

Chrome Stable Channel Update for Desktop (2025.12.11)

 修正 3 件のうち CVE-2025-14174 が 0-day だったわけですが、

[N/A][466192044] High CVE-2025-14174: Out of bounds memory access in ANGLE. Reported by Apple Security Engineering and Architecture (SEAR) and Google Threat Analysis Group on 2025-12-05
(中略)
Google is aware that an exploit for CVE-2025-14174 exists in the wild.

 これ WebKit 関連で iOS < 26 に対する攻撃が確認されているという話だったのですね。 Apple でも修正かかってます。

  • About the security content of iOS 18.7.3 and iPadOS 18.7.3 (Apple, 2025.12.12)

    WebKit

    Available for: iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later

    Impact: Processing maliciously crafted web content may lead to memory corruption. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-43529 was also issued in response to this report.

    Description: A memory corruption issue was addressed with improved validation.
    WebKit Bugzilla: 303614

    CVE-2025-14174: Apple and Google Threat Analysis Group

 あと Edge。

2025.12.25 追記:

 WebKitGTK and WPE WebKit Security Advisory WSA-2025-0010 (oss-sec ML, 2025.12.17)。 CVE-2025-43529, CVE-2025-14174 の修正が含まれています。


■ 2025.12.12


■ 2025.12.11

■ いろいろ (2025.12.11)
(various)

Zoom

■ Adobe 方面 (ColdFusion, Experience Manager, DNG SDK, Acrobat / Acrobat Reader, Cloud Desktop)
(Adobe, 2025.12.09)

 Adobe 2025.12 Security Bulletin です。 ColdFusion のみ Priority: 1、他は Priority: 3 です。

■ 追記

Firefox 146.0 / ESR 140.6.0 / ESR 115.31.0 公開 (2025.12.10)

 Thunderbird 146 / 140.6.0esr も出ました。

■ Chrome Stable Channel Update for Desktop
(Google, 2025.12.10)

 Chrome 143.0.7499.109/.110 (Windows / Mac) および 143.0.7499.109 (Linux) 公開。3 件のセキュリティ修正を含む。関連:

2025.12.15 追記:

 修正 3 件のうち CVE-2025-14174 が 0-day だったわけですが、

[N/A][466192044] High CVE-2025-14174: Out of bounds memory access in ANGLE. Reported by Apple Security Engineering and Architecture (SEAR) and Google Threat Analysis Group on 2025-12-05
(中略)
Google is aware that an exploit for CVE-2025-14174 exists in the wild.

 これ WebKit 関連で iOS < 26 に対する攻撃が確認されているという話だったのですね。 Apple でも修正かかってます。

 あと Edge。


■ 2025.12.10

■ 2025 年 12 月のセキュリティ更新プログラム (月例)
(Microsoft, 2025.12.09)

 Microsoft 2025.12 更新。 57 Microsoft CVE + 13 non-MS CVE。 CVE 番号が太字 なのは critical (最大深刻度: 緊急) 扱い。 (Security Update Guide から拾っています)

 0-day は 3 件だそうです。

 関連:

2025.12.19 追記:

 MSMQ に不具合発生。対応 patch が公開されている。

2025.12.23 追記:

 トレンドマイクロ Apex One や ビジネスセキュリティ サービス で不具合が発生しているそうで。

■ Firefox 146.0 / ESR 140.6.0 / ESR 115.31.0 公開
(Mozilla, 2025.12.09)

 出ました。

2025.12.11 追記:

 Thunderbird 146 / 140.6.0esr も出ました。

2025.12.19 追記:

 Firefox 146.0.1、Firefox for Android 146.0.1、 Thunderbird 146.0.1 が公開されている。 Firefox 146.0.1、Firefox for Android 146.0.1 にはセキュリティ修正が含まれる。

■ 追記

Critical Security Vulnerability in React Server Components (2025.12.05)


■ 2025.12.09

■ いろいろ (2025.12.09)
(various)

PowerDNS Recursor


■ 2025.12.08

■ いろいろ (2025.12.08)
(various)

Wireshark

Go


■ 2025.12.05

■ Critical Security Vulnerability in React Server Components
(React.js, 2025.12.03)

 React.js 19.0 / 19.1.0 / 19.1.1 / 19.2.0 の

に RCE を招く欠陥 CVE-2025-55182。CVSS v3.1 10.0 (満点)。React.js 19.0.1 / 19.1.2 / 19.2.1 で修正。

 React.js を使った Web アプリケーションフレームワーク Next.js にも影響があり CVE-2025-66478、 Next.js 15.0.5 / 15.1.9 / 15.2.6 / 15.3.6 / 15.4.8 / 15.5.7 / 16.0.7 で修正されている。

 関連:

2025.12.10 追記:

 関連:

■ Apache httpd 2.4.66 ChangeLog
(apache.org, 2025.12.04)

 Apache httpd 2.4.66 公開。セキュリティ修正 5 件を含む。 iida さん情報ありがとうございます。

 mod_md - Managing domains across virtual hosts, certificate provisioning via the ACME protocol というものがあるのですね。現時点では Experimental 扱いのようですが。


■ 2025.12.04


■ 2025.12.03

■ いろいろ (2025.12.03)
(various)

各種 ICS

Django

Kubernetes

CUPS

X.Org xkbcomp

Windows 版 Vim

■ Array Networks Array AGシリーズにおけるコマンドインジェクションの脆弱性に関する注意喚起
(JPCERT/CC, 2025.12.03)

 Array AG シリーズの「DesktopDirect機能」にコマンドインジェクションを許す欠陥があるそうで。 2025.05 リリースの ArrayOS AG 9.4.5.9 で修正済だそうだが、 国内攻撃事例を 2025.08 以降に確認しているそうで。

攻撃時期:2025年8月以降
攻撃内容:webshell設置※、同製品上で新規ユーザー作成、同製品経由での内部侵入など
攻撃痕跡:攻撃通信の送信元IPアドレス
- 194.233.100[.]138

 本件、https://support.arraynetworks.net/prx/001/http/supportportal.arraynetworks.net/appnotes.html にある「Array Networks Security Advisory: Enhance DesktopDirect Security」 のことかなあ。 要認証のため読めないのですが。

■ Chrome Stable Channel Update for Desktop
(Google, 2025.12.02)

 Chrome 143.0.7499.40 (Linux) および 143.0.7499.40/41 (Windows, Mac) が stable に。13 件のセキュリティ修正を含む。関連:


■ 2025.12.02

■ いろいろ (2025.12.02)
(various)

Advantech WebAccess/VPN

unbound

Android

Wireshark

PostgreSQL

pgAdmin


■ 2025.12.01


[セキュリティホール memo]
[私について]