¡¾Îó²îͨ¸æ¡¿OpenVPN DCOÇý¶¯³ÌÐò»º³åÇøÒç³öÎó²î (CVE-2025-50054)

Ðû²¼Ê±¼ä 2025-06-23

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

OpenVPN DCOÇý¶¯³ÌÐò»º³åÇøÒç³öÎó²î

CVE   ID

CVE-2025-50054

Îó²îÀàÐÍ

»º³åÇøÒç³öÎó²î

·¢Ã÷ʱ¼ä

2025-06-23

Îó²îÆÀ·Ö

9.8

Îó²îÆ·¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍâµØ

ËùÐèȨÏÞ

µÍ

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

²»ÐèÒª

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


OpenVPNÊÇÒ»¿î¿ªÔ´µÄÐéÄâ˽ÈËÍøÂ磨VPN£©Èí¼þ£¬£¬£¬£¬Ê¹ÓÃSSL/TLSЭÒéʵÏÖ¼ÓÃÜͨѶ£¬£¬£¬£¬Ö§³Öµã¶ÔµãºÍÕ¾µãµ½Õ¾µãµÄÇå¾²ÅþÁ¬£¬£¬£¬£¬ÆÕ±éÓ¦ÓÃÓÚÔ¶³Ì»á¼ûºÍÆóÒµÍøÂç¡£¡£¡£¡£¡£ËüÖ§³Ö¶àÖÖÉí·ÝÑéÖ¤·½·¨£¬£¬£¬£¬°üÀ¨Ô¤¹²ÏíÃÜÔ¿¡¢Êý×ÖÖ¤ÊéºÍÓû§Ãû/ÃÜÂë×éºÏ¡£¡£¡£¡£¡£Í¨¹ýʹÓÃOpenSSL¼ÓÃܿ⣬£¬£¬£¬OpenVPNÌṩ¸ß´ï256λµÄ¼ÓÃÜÇ¿¶È£¬£¬£¬£¬²¢Ö§³ÖÍêÉÆÇ°Ïò±£ÃÜ£¨PFS£©¹¦Ð§£¬£¬£¬£¬ÔöÇ¿Êý¾ÝÇå¾²ÐÔ¡£¡£¡£¡£¡£OpenVPN¼æÈݶàÖÖ²Ù×÷ϵͳ£¬£¬£¬£¬ÈçWindows¡¢Linux¡¢macOS¡¢iOSºÍAndroid£¬£¬£¬£¬ÊÊÓÃÓÚ¼ÒÍ¥Óû§¡¢ÆóÒµºÍ¿ª·¢Õߣ¬£¬£¬£¬ÒòÆä¸ßÇå¾²ÐÔ¡¢ÎÞаÐԺͿªÔ´ÌØÕ÷£¬£¬£¬£¬³ÉΪȫÇò×îÊܽӴýµÄVPN½â¾ö¼Æ»®Ö®Ò»¡£¡£¡£¡£¡£


2025Äê6ÔÂ23ÈÕ£¬£¬£¬£¬¼øºÚµ£±£Íø¼¯ÍÅVSRC¼à²âµ½openvpnÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬Åû¶openvpnÖеÄÒ»¸ö»º³åÇøÒç³öÎó²î¡£¡£¡£¡£¡£¸ÃÎó²î±£´æÓÚOpenVPNµÄWindowsÊý¾ÝͨµÀÐ¶ÔØÇý¶¯³ÌÐò£¨ovpn-dco-win£©ÖУ¬£¬£¬£¬µ±Óû§¿Õ¼äÀú³ÌÏòÄÚºËÇý¶¯³ÌÐò·¢ËÍÁè¼Ý1500×ֽڵĿØÖÆÐÂÎÅʱ£¬£¬£¬£¬»áµ¼ÖÂWindows DCOÇý¶¯³ÌÐòÍ߽⡣¡£¡£¡£¡£´ËÎó²î½öÄÜͨ¹ýÍâµØÀú³Ì´¥·¢£¬£¬£¬£¬¶ø·ÇÔ¶³Ì¹¥»÷£¬£¬£¬£¬ÇÒ×ÝÈ»ÊÇ·ÇÌØÈ¨Àú³ÌÒ²ÄÜʹÓôËÎó²î¡£¡£¡£¡£¡£OpenVPN×Ô¼º¾ßÓÐÏÞÖÆ£¬£¬£¬£¬²»»á·¢Ëͳ¬³¤ÐÂÎÅ£¬£¬£¬£¬µ«×Ô½ç˵±àÒëµÄOpenVPN»òÆäËûÓëDCOÇý¶¯³ÌÐò½»»¥µÄÀú³Ì¿ÉÄÜÈÆ¹ý¸ÃÏÞÖÆ£¬£¬£¬£¬´¥·¢Îó²î¡£¡£¡£¡£¡£¸ÃÎó²î¿ÉÄܵ¼ÖÂϵͳ²»ÎȹÌ¡£¡£¡£¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


ovpn-dco-win ¡Ü 1.3.0
2.6.0-I005 ¡Ü OpenVPN GUI for Windows ¡Ü 2.6.14-I001
OpenVPN GUI for Windows = 2.7_alpha1-I001


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


½¨ÒéÉý¼¶OpenVPN GUI for WindowsÖÁÈçϰ汾
OpenVPN GUI for Windows ¡Ý 2.6.14-I002
OpenVPN GUI for Windows ¡Ý 2.7_alpha2-I001¡£¡£¡£¡£¡£


ÏÂÔØÁ´½Ó£ºhttps://openvpn.net/community-downloads/


3.2 ÔÝʱ²½·¥


ÔÝÎÞ¡£¡£¡£¡£¡£


3.3 ͨÓý¨Òé


?°´ÆÚ¸üÐÂϵͳ²¹¶¡£¡£¡£¡£¡£¬£¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£
?ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£¡£¡£
?ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£
?ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£
?ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://community.openvpn.net/Security%20Announcements/CVE-2025-50054
https://nvd.nist.gov/vuln/detail/CVE-2025-50054