¡¾·ì϶¹«¸æ¡¿7-Zip Mark-of-the-WebÈÆ¹ý·ì϶(CVE-2025-0411)
°ä²¼¹¦·ò 2025-01-22Ò»¡¢¡¢·ì϶¸ÅÊö
·ì϶Ãû³Æ | 7-Zip Mark-of-the-WebÈÆ¹ý·ì϶ | ||
CVE ID | CVE-2025-0411 | ||
·ì϶ÀàÐÍ | °²È«»úÖÆÈÆ¹ý | ·¢ÏÖ¹¦·ò | 2025-01-22 |
·ì϶ÆÀ·Ö | 7.0 | ·ì϶µÈ¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ±¾µØ | ËùÐèȨÏÞ | µÍ |
ÀûÓÃÄÑ¶È | ¸ß | Óû§½»»¥ | ±ØÒª |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
7-Zip ÊÇÒ»¸ö¿ªÔ´µÄÎļþѹËõºÍ½âѹËõÈí¼þ£¬£¬£¬Ö§³Ö¶àÖÖѹËõÌåʽ£¬£¬£¬Èç 7z¡¢¡¢ZIP¡¢¡¢RAR¡¢¡¢TAR µÈ¡£¡£¡£¡£Ëüѡȡ¸ßЧµÄѹËõËã·¨£¬£¬£¬Ìṩ±È´«Í³Ñ¹Ëõ¹¤¾ß¸ü¸ßµÄѹËõ±È£¬£¬£¬ÇÒÖ§³Ö¼ÓÃܺͷ־íѹËõ¡£¡£¡£¡£7-Zip ÓµÓе¥Ò»Ò×ÓõĽçÃæ£¬£¬£¬ºÏÓÃÓÚWindowsºÍLinuxϵͳ£¬£¬£¬¿í·ºÀûÓÃÓÚÎļþ´æ´¢ºÍ´«Êä¡£¡£¡£¡£
2025Äê1ÔÂ22ÈÕ£¬£¬£¬OG¶«·½Ìü¼¯ÍÅVSRC¼à²âµ½ Zero Day Initiative °ä²¼Á˹ØÓÚ CVE-2025-0411 ·ì϶µÄ²¼¸æ¡£¡£¡£¡£²¼¸æÖ¸³ö£¬£¬£¬¸Ã·ì϶ÔÊÐíÔ¶³Ì¹¥»÷ÕßÈÆ¹ý 7-Zip ÔÚÊÜÓ°ÏìϵͳÖÐµÄ Mark-of-the-Web±£»¤»úÖÆ¡£¡£¡£¡£ÀûÓô˷ì϶±ØÒªÓû§½»»¥£¬£¬£¬¼´Ö¸±ê±ØÐë½Ó¼û¶ñÒâÍøÒ³»ò´ò¿ª¶ñÒâÎļþ¡£¡£¡£¡£·ì϶¾ßÌå´æÔÚÓڹ鵵ÎļþµÄ´¦Öùý³ÌÖУ¬£¬£¬µ±´Ó´øÓÐ Mark-of-the-WebÏóÕ÷µÄ¶ñÒâ¹éµµÖÐÌáÈ¡Îļþʱ£¬£¬£¬7-Zip δÄܽ«¸ÃÏóÕ÷ÕýÈ·´«²¼µ½ÌáÈ¡µÄÎļþ¡£¡£¡£¡£¹¥»÷Õ߿ɽè´Ë·ì϶£¬£¬£¬ÔÚµ±Ç°Óû§È¨ÏÞÏÂÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£
¶þ¡¢¡¢Ó°ÏìÁìÓò
7-Zip < 24.09
Èý¡¢¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
3.2 һʱ´ëÊ©
ÉóÉ÷´¦Öò»ÊÜÐÅÀµµÄÎļþ£¬£¬£¬Ô¤·À´ò¿ªÀ´×Ôδ֪»ò¿ÉÒÉÆðÔ´µÄѹËõµµ°¸¡£¡£¡£¡£È·±£²Ù×÷ϵͳºÍ°²È«Èí¼þÕýÈ·ÅäÖ㬣¬£¬ÒÔ¼ì²âºÍ×èÖ¹¶ñÒâÎļþµÄÖ´ÐУ¬£¬£¬³ö¸ñÊÇÀ´×Ô²»³ÉÐÅÆðÔ´µÄÎļþ¡£¡£¡£¡£
3.3 ͨÓý¨Òé
? ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£¡£¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ