¡¾Îó²îͨ¸æ¡¿7-Zip Mark-of-the-WebÈÆ¹ýÎó²î(CVE-2025-0411)
Ðû²¼Ê±¼ä 2025-01-22Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | 7-Zip Mark-of-the-WebÈÆ¹ýÎó²î | ||
CVE ID | CVE-2025-0411 | ||
Îó²îÀàÐÍ | Çå¾²»úÖÆÈÆ¹ý | ·¢Ã÷ʱ¼ä | 2025-01-22 |
Îó²îÆÀ·Ö | 7.0 | Îó²îÆ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍâµØ | ËùÐèȨÏÞ | µÍ |
ʹÓÃÄÑ¶È | ¸ß | Óû§½»»¥ | ÐèÒª |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
7-Zip ÊÇÒ»¸ö¿ªÔ´µÄÎļþѹËõÏ¢ÕùѹËõÈí¼þ£¬£¬£¬£¬Ö§³Ö¶àÖÖѹËõÃûÌ㬣¬£¬£¬Èç 7z¡¢ZIP¡¢RAR¡¢TAR µÈ¡£¡£¡£¡£¡£Ëü½ÓÄɸßЧµÄѹËõËã·¨£¬£¬£¬£¬Ìṩ±È¹Å°åѹËõ¹¤¾ß¸ü¸ßµÄѹËõ±È£¬£¬£¬£¬ÇÒÖ§³Ö¼ÓÃܺͷ־íѹËõ¡£¡£¡£¡£¡£7-Zip ¾ßÓмòÆÓÒ×ÓõĽçÃæ£¬£¬£¬£¬ÊÊÓÃÓÚWindowsºÍLinuxϵͳ£¬£¬£¬£¬ÆÕ±éÓ¦ÓÃÓÚÎļþ´æ´¢ºÍ´«Êä¡£¡£¡£¡£¡£
2025Äê1ÔÂ22ÈÕ£¬£¬£¬£¬¼øºÚµ£±£Íø¼¯ÍÅVSRC¼à²âµ½ Zero Day Initiative Ðû²¼Á˹ØÓÚ CVE-2025-0411 Îó²îµÄͨ¸æ¡£¡£¡£¡£¡£Í¨¸æÖ¸³ö£¬£¬£¬£¬¸ÃÎó²îÔÊÐíÔ¶³Ì¹¥»÷ÕßÈÆ¹ý 7-Zip ÔÚÊÜÓ°ÏìϵͳÖÐµÄ Mark-of-the-Web±£»£»£»£»£»£»¤»úÖÆ¡£¡£¡£¡£¡£Ê¹ÓôËÎó²îÐèÒªÓû§½»»¥£¬£¬£¬£¬¼´Ä¿µÄ±ØÐè»á¼û¶ñÒâÍøÒ³»ò·¿ª¶ñÒâÎļþ¡£¡£¡£¡£¡£Îó²îÏêϸ±£´æÓڹ鵵ÎļþµÄ´¦Öóͷ£Àú³ÌÖУ¬£¬£¬£¬µ±´Ó´øÓÐ Mark-of-the-Web±ê¼ÇµÄ¶ñÒâ¹éµµÖÐÌáÈ¡Îļþʱ£¬£¬£¬£¬7-Zip δÄܽ«¸Ã±ê¼Ç׼ȷÈö²¥µ½ÌáÈ¡µÄÎļþ¡£¡£¡£¡£¡£¹¥»÷Õ߿ɽè´ËÎó²î£¬£¬£¬£¬ÔÚÄ¿½ñÓû§È¨ÏÞÏÂÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
7-Zip < 24.09
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
3.2 ÔÝʱ²½·¥
ÉóÉ÷´¦Öóͷ£²»ÊÜÐÅÈεÄÎļþ£¬£¬£¬£¬×èÖ¹·¿ªÀ´×Ôδ֪»ò¿ÉÒÉȪԴµÄѹËõµµ°¸¡£¡£¡£¡£¡£È·±£²Ù×÷ϵͳºÍÇå¾²Èí¼þ׼ȷÉèÖ㬣¬£¬£¬ÒÔ¼ì²âºÍ×èÖ¹¶ñÒâÎļþµÄÖ´ÐУ¬£¬£¬£¬ÌØÊâÊÇÀ´×Ô²»¿ÉÐÅȪԴµÄÎļþ¡£¡£¡£¡£¡£
3.3 ͨÓý¨Òé
? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£