¡¾·ì϶¹«¸æ¡¿7-Zip Mark-of-the-WebÈÆ¹ý·ì϶(CVE-2025-0411)

°ä²¼¹¦·ò 2025-01-22

Ò»¡¢·ì϶¸ÅÊö


·ìϼûû³Æ

7-Zip Mark-of-the-WebÈÆ¹ý·ì϶

CVE   ID

CVE-2025-0411

·ì϶ÀàÐÍ

°²È«»úÔìÈÆ¹ý

·¢ÏÖ¹¦·ò

2025-01-22

·ì϶ÆÀ·Ö

7.0

·ì϶µÈ¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

±¾µØ

ËùÐèȨÏÞ

µÍ

ÀûÓÃÄѶÈ

¸ß

Óû§½»»¥

±ØÒª

PoC/EXP

δ¹«¿ª

ÔÚÒ°ÀûÓÃ

δ·¢ÏÖ


7-Zip ÊÇÒ»¸ö¿ªÔ´µÄÎļþѹËõºÍ½âѹËõÈí¼þ£¬Ö§³Ö¶àÖÖѹËõÌåʽ£¬Èç 7z¡¢ZIP¡¢RAR¡¢TAR µÈ¡£Ëüѡȡ¸ßЧµÄѹËõËã·¨£¬Ìṩ±È´«Í³Ñ¹Ëõ¹¤¾ß¸ü¸ßµÄѹËõ±È£¬ÇÒÖ§³Ö¼ÓÃܺͷ־íѹËõ¡£7-Zip ÓµÓе¥Ò»Ò×ÓõĽçÃæ£¬ºÏÓÃÓÚWindowsºÍLinuxϵͳ£¬¿í·ºÀûÓÃÓÚÎļþ´æ´¢ºÍ´«Êä¡£


2025Äê1ÔÂ22ÈÕ£¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½ Zero Day Initiative °ä²¼Á˹ØÓÚ CVE-2025-0411 ·ì϶µÄ²¼¸æ¡£²¼¸æÖ¸³ö£¬¸Ã·ì϶ÔÊÐíÔ¶³Ì¹¥»÷ÕßÈÆ¹ý 7-Zip ÔÚÊÜÓ°ÏìϵͳÖÐµÄ Mark-of-the-Web±£»¤»úÔì¡£ÀûÓô˷ì϶±ØÒªÓû§½»»¥£¬¼´Ö¸±ê±ØÐë½Ó¼û¶ñÒâÍøÒ³»ò´ò¿ª¶ñÒâÎļþ¡£·ì϶¾ßÌå´æÔÚÓڹ鵵ÎļþµÄ´¦Öùý³ÌÖУ¬µ±´Ó´øÓÐ Mark-of-the-WebÏóÕ÷µÄ¶ñÒâ¹éµµÖÐÌáÈ¡Îļþʱ£¬7-Zip δÄܽ«¸ÃÏóÕ÷ÕýÈ·´«²¼µ½ÌáÈ¡µÄÎļþ¡£¹¥»÷Õ߿ɽè´Ë·ì϶£¬ÔÚµ±Ç°Óû§È¨ÏÞÏÂÖ´ÐÐËÁÒâ´úÂë¡£


¶þ¡¢Ó°ÏìÁìÓò


7-Zip < 24.09


Èý¡¢°²È«´ëÊ©


3.1 Éý¼¶°æ±¾


Ŀǰ¸Ã·ì϶ÒÑÔÚ7-Zip 24.09°æ±¾Öн¨¸´£¬Ç뾡¿ìÏÂÔØ²¢Éý¼¶ÖÁ×îа汾
ÏÂÔØÁ´½Ó£º
https://7-zip.org/download.html


3.2 һʱ´ëÊ©


ÉóÉ÷´¦Öò»ÊÜÐÅÀµµÄÎļþ£¬Ô¤·À´ò¿ªÀ´×Ôδ֪»ò¿ÉÒÉÆðÔ´µÄѹËõµµ°¸¡£È·±£²Ù×÷ϵͳºÍ°²È«Èí¼þÕýÈ·ÅäÖã¬ÒÔ¼ì²âºÍ×èÖ¹¶ñÒâÎļþµÄÖ´ÐУ¬³ö¸ñÊÇÀ´×Ô²»³ÉÐÅÆðÔ´µÄÎļþ¡£


3.3 ͨÓý¨Òé


? ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£
¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ¡£
ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£
¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£

ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£


3.4 ²Î¿¼Á´½Ó


https://www.zerodayinitiative.com/advisories/ZDI-25-045/