¡¾·ì϶¹«¸æ¡¿Windows Admin Center ±¾µØÈ¨ÏÞÌáÉý·ì϶(CVE-2025-64669)
°ä²¼¹¦·ò 2025-12-17Ò»¡¢·ì϶¸ÅÊö
·ìϼûû³Æ | Windows Admin Center ±¾µØÈ¨ÏÞÌáÉý·ì϶ | ||
CVE ID | CVE-2025-64669 | ||
·ì϶ÀàÐÍ | ±¾µØÈ¨ÏÞÌáÉý | ·¢ÏÖ¹¦·ò | 2025-12-17 |
·ì϶ÆÀ·Ö | 7.8 | ·ì϶µÈ¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ±¾µØ | ËùÐèȨÏÞ | µÍ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»±ØÒª |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
Windows Admin Center£¨WAC£©ÊÇ΢ÈíΪWindows ServerºÍWindows 10/11ÌṩµÄ¼¯ÖÐÖÎÀí¹¤¾ß£¬Ö¼ÔÚ¼ò»¯·þÎñÆ÷ºÍ»ù´¡ÉèÊ©µÄÖÎÀí¡£ËüÌṩÁËͨ¹ýͼÐÎÓû§½çÃæ£¨GUI£©½øÐзþÎñÆ÷ÖÎÀí¡¢¼à¿ØºÍÅäÖõÄÖ°ÄÜ£¬Ö§³Ö¶àÖÖ²Ù×÷ϵͳºÍ·þÎñ£¬ÈçHyper-V¡¢¼¯ÈºÖÎÀí¡¢Ô¶³Ì×ÀÃæ¡¢´æ´¢ÖÎÀíµÈ¡£WACÄܹ»Í¨¹ýWebä¯ÀÀÆ÷½Ó¼û£¬ÔÊÐíÖÎÀíÔ±Ô¶³Ì²Ù×÷ºÍÊØ»¤¶à¸ö·þÎñÆ÷£¬ÌáÉýITÔËάЧÄÜ¡£
2025Äê12ÔÂ17ÈÕ£¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½Î¢ÈíWindows Admin Center£¨WAC£©Öеı¾µØÈ¨ÏÞÌáÉý·ì϶£¬¸Ã·ì϶ԴÓÚC:\ProgramData\WindowsAdminCenterĿ¼µÄĿ¼ȨÏÞÉèÖò»µ±£¬¸ÃĿ¼¶Ôͨ³£Óû§¿Éд£¬µ«È´ÓÉÒÔ¸ßȨÏÞÔËÐеķþÎñʹÓ᣹¥»÷ÕßÄܹ»ÀûÓôËȱµã£¬Í¨¹ýÏò¸ÃĿ¼¸éÖöñÒâPowerShell¾ç±¾»òDLLÎļþ£¬´Ó¶øÊµÏÖȨÏÞÌáÉý£¬»ñȡϵͳȨÏÞ¡£Cymulate×êÑÐÈËԱͨ¹ýÁ½ÖÖ¶ÀÁ¢µÄ¹¥»÷Á´Õ¹Ê¾Á˸÷ì϶µÄ·çÏÕ£ºÒ»ÊÇÀûÓÃÀ©´óÐ¶ÔØ»úÔ죬¶þÊÇͨ¹ýDLL½Ù³ÖWAC¸üз¨Ê½¡£¸Ã·ì϶µÄ´æÔÚÑϳÁ¼õÈõÁËWindowsϵͳµÄȨÏÞ¸ôÀ룬¹¥»÷Õß½öÐè±¾µØÓû§È¨ÏÞ¼´¿ÉÌáÉýÖÁSYSTEMȨÏÞ¡£
¶þ¡¢Ó°ÏìÁìÓò
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£ºhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-64669/
3.2 һʱ´ëÊ©
ÔÝÎÞ¡£


¾©¹«Íø°²±¸11010802024551ºÅ