¡¾Îó²îͨ¸æ¡¿7-Zip Mark-of-the-WebÈƹýÎó²î(CVE-2025-0411)
Ðû²¼Ê±¼ä 2025-01-22Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | 7-Zip Mark-of-the-WebÈƹýÎó²î | ||
CVE ID | CVE-2025-0411 | ||
Îó²îÀàÐÍ | Çå¾²»úÖÆÈƹý | ·¢Ã÷ʱ¼ä | 2025-01-22 |
Îó²îÆÀ·Ö | 7.0 | Îó²îÆ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍâµØ | ËùÐèȨÏÞ | µÍ |
ʹÓÃÄÑ¶È | ¸ß | Óû§½»»¥ | ÐèÒª |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
7-Zip ÊÇÒ»¸ö¿ªÔ´µÄÎļþѹËõÏ¢ÕùѹËõÈí¼þ£¬Ö§³Ö¶àÖÖѹËõÃûÌã¬Èç 7z¡¢ZIP¡¢RAR¡¢TAR µÈ¡£Ëü½ÓÄɸßЧµÄѹËõËã·¨£¬Ìṩ±È¹Å°åѹËõ¹¤¾ß¸ü¸ßµÄѹËõ±È£¬ÇÒÖ§³Ö¼ÓÃܺͷ־íѹËõ¡£7-Zip ¾ßÓмòÆÓÒ×ÓõĽçÃ棬ÊÊÓÃÓÚWindowsºÍLinuxϵͳ£¬ÆÕ±éÓ¦ÓÃÓÚÎļþ´æ´¢ºÍ´«Êä¡£
2025Äê1ÔÂ22ÈÕ£¬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø¼¯ÍÅVSRC¼à²âµ½ Zero Day Initiative Ðû²¼Á˹ØÓÚ CVE-2025-0411 Îó²îµÄͨ¸æ¡£Í¨¸æÖ¸³ö£¬¸ÃÎó²îÔÊÐíÔ¶³Ì¹¥»÷ÕßÈƹý 7-Zip ÔÚÊÜÓ°ÏìϵͳÖÐµÄ Mark-of-the-Web±£»¤»úÖÆ¡£Ê¹ÓôËÎó²îÐèÒªÓû§½»»¥£¬¼´Ä¿µÄ±ØÐè»á¼û¶ñÒâÍøÒ³»ò·¿ª¶ñÒâÎļþ¡£Îó²îÏêϸ±£´æÓڹ鵵ÎļþµÄ´¦Öóͷ£Àú³ÌÖУ¬µ±´Ó´øÓÐ Mark-of-the-Web±ê¼ÇµÄ¶ñÒâ¹éµµÖÐÌáÈ¡Îļþʱ£¬7-Zip δÄܽ«¸Ã±ê¼Ç׼ȷÈö²¥µ½ÌáÈ¡µÄÎļþ¡£¹¥»÷Õ߿ɽè´ËÎó²î£¬ÔÚÄ¿½ñÓû§È¨ÏÞÏÂÖ´ÐÐí§Òâ´úÂë¡£
¶þ¡¢Ó°Ïì¹æÄ£
7-Zip < 24.09
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
3.2 ÔÝʱ²½·¥
ÉóÉ÷´¦Öóͷ£²»ÊÜÐÅÍеÄÎļþ£¬×èÖ¹·¿ªÀ´×Ôδ֪»ò¿ÉÒÉȪԴµÄѹËõµµ°¸¡£È·±£²Ù×÷ϵͳºÍÇå¾²Èí¼þ׼ȷÉèÖã¬ÒÔ¼ì²âºÍ×èÖ¹¶ñÒâÎļþµÄÖ´ÐУ¬ÌØÊâÊÇÀ´×Ô²»¿ÉÐÅȪԴµÄÎļþ¡£
3.3 ͨÓý¨Òé
? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£