1. Analysis of vulnerabilities
Recently, the national information security vulnerability sharing platform released a security notice that there is a remote code execution vulnerability in the Sunflower remote control software of Shanghai Bayui Information Technology Co., LTD.CNVD-2022-10270) and (CNVD-2022-03672)。Sunflower is a free, set remote control computer mobile phone, remote desktop connection, remote boot, remote management, support Intranet penetration of the integrated remote control management tool software。At present, a demo video of the vulnerability has been published, and relevant users are requested to take measures to protect it as soon as possible。
2. Scope of vulnerability
CNVD-2022-10270: Sunflower Personal Edition for Windows 11.0.0.33
CNVD-2022-03672: Sunflower Version V1.0.1.43315(2021.12)
3. Suggestions on vulnerability disposal
Officials have released a new version of this vulnerability fix, it is recommended that affected users update in time to protect。
The above article is fromCNVD Vulnerability Platform, by CNVD