Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | 7-Zip Ŀ¼´©Ô½µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐÎó²î |
CVE ID | CVE-2025-11001 |
Îó²îÀàÐÍ | Ŀ¼´©Ô½ | ·¢Ã÷ʱ¼ä | 2025-10-16 |
Îó²îÆÀ·Ö | 7.0 | Îó²îÆ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍâµØ | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | ¸ß | Óû§½»»¥ | ÐèÒª |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
7-ZipÊÇÒ»¿î¿ªÔ´µÄÎļþѹËõÏ¢ÕùѹËõÈí¼þ£¬£¬£¬£¬£¬£¬Ö§³Ö¶àÖÖÎļþÃûÌ㬣¬£¬£¬£¬£¬°üÀ¨7z¡¢ZIP¡¢RAR¡¢TAR¡¢GZµÈ¡£¡£ËüÒÔ¸ßѹËõ±ÈºÍÇáÓ¯µÄ²Ù×÷½çÃæÖø³Æ£¬£¬£¬£¬£¬£¬Äܹ»ÓÐÓõؼõСÎļþ¾Þϸ£¬£¬£¬£¬£¬£¬Í¬Ê±¼á³ÖÓÅÒìµÄѹËõЧÂÊ¡£¡£7-ZipʹÓÃ×Ô¼ºµÄ7zÃûÌ㬣¬£¬£¬£¬£¬¸ÃÃûÌþßÓиü¸ßµÄѹËõÂÊ£¬£¬£¬£¬£¬£¬²¢Ö§³ÖÇ¿¼ÓÃÜËã·¨¡£¡£7-ZipÖ§³Ö¿çƽ̨²Ù×÷£¬£¬£¬£¬£¬£¬³ýÁËWindows£¬£¬£¬£¬£¬£¬LinuxºÍmacOSÒ²¿ÉÒÔʹÓÃp7zip°æ±¾¡£¡£7-ZipÌṩÁËÏÂÁîÐнçÃæºÍͼÐÎÓû§½çÃæ£¨GUI£©£¬£¬£¬£¬£¬£¬Êʺϲî±ðÓû§µÄÐèÇ󣬣¬£¬£¬£¬£¬ÆÕ±éÓ¦ÓÃÓÚÒ»Ñùƽ³£ÎļþѹËõ¡¢¼ÓÃÜÏ¢ÕùѹÊÂÇéÖС£¡£
2025Äê10ÔÂ16ÈÕ£¬£¬£¬£¬£¬£¬ÄϹ¬NGÓéÀÖ¼¯ÍÅVSRC¼à²âµ½Ò»¸öÓ°Ïì7-ZipѹËõ¹¤¾ßµÄĿ¼´©Ô½Îó²î£¨CVE-2025-11001£©£¬£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚZIPÎļþÖзûºÅÁ´½Ó£¨symlink£©µÄ´¦Öóͷ£·½·¨¡£¡£¹¥»÷Õß¿Éͨ¹ý½á¹¹¶ñÒâZIPÎļþ£¬£¬£¬£¬£¬£¬Ê¹ÓøÃĿ¼±éÀúÎó²î£¬£¬£¬£¬£¬£¬µ¼Ö³ÌÐò»á¼ûδ¾ÊÚȨµÄĿ¼²¢Ö´ÐжñÒâ´úÂë¡£¡£Í¬Ê±£¬£¬£¬£¬£¬£¬7-ZipѹËõ¹¤¾ß»¹±£´æÁíÒ»¸öÀàËÆÎó²î£¨CVE-2025-11002£©£¬£¬£¬£¬£¬£¬Á½¸öÎó²î¾ùÔÊÐíÔ¶³Ì¹¥»÷ÕßÔÚÊÜÓ°ÏìµÄϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£Í¨¹ýÌØÖÆµÄZIPÎļþ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Ê¹Ó÷ûºÅÁ´½Ó´¦Öóͷ£È±ÏÝ£¬£¬£¬£¬£¬£¬´Ùʹ³ÌÐò»á¼û±¾²»Ó¦»á¼ûµÄĿ¼£¬£¬£¬£¬£¬£¬½ø¶øÖ´ÐжñÒâ´úÂë¡£¡£ÕâÁ½¸öÎó²îµÄʹÓ÷½·¨ÏàËÆ£¬£¬£¬£¬£¬£¬¾ù¿Éµ¼ÖÂϵͳÇ徲Σº¦¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
7-Zip < 25.00
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
7-Zip¹Ù·½ÒÑÐû²¼ÐÞ¸´²¹¶¡£¬£¬£¬£¬£¬£¬ÒÔÐÞ¸´¸ÃÎó²î¡£¡£
ÏÂÔØÁ´½Ó£ºhttps://github.com/ip7z/7zip/releases/
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£
3.3 ͨÓý¨Òé
? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£? ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£? ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£? ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£
3.4 ²Î¿¼Á´½Ó
https://www.zerodayinitiative.com/advisories/ZDI-25-950/https://www.zerodayinitiative.com/advisories/ZDI-25-949/