¡¾Îó²îͨ¸æ¡¿WinRAR ·¾¶´¦Öóͷ£Îó²îµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ (CVE-2025-6218)

Ðû²¼Ê±¼ä 2025-06-25

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

WinRAR ·¾¶´¦Öóͷ£Îó²îµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ

CVE   ID

CVE-2025-6218

Îó²îÀàÐÍ

RCE

·¢Ã÷ʱ¼ä

2025-06-25

Îó²îÆÀ·Ö

7.8

Îó²îÆ·¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍâµØ

ËùÐèȨÏÞ

ÎÞ

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

ÐèÒª

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


WinRARÊÇÒ»¿îÆÕ±éʹÓõÄÎļþѹËõÏ¢ÕùѹÈí¼þ£¬£¬£¬£¬ £¬£¬£¬Ö§³Ö¶àÖÖѹËõÃûÌ㬣¬£¬£¬ £¬£¬£¬ÈçRAR¡¢ZIPºÍÆäËû³£¼ûÃûÌᣡ£¡£¡£¡£¡£¡£ËüÌṩǿʢµÄѹËõºÍ¼ÓÃܹ¦Ð§£¬£¬£¬£¬ £¬£¬£¬ÔÊÐíÓû§½¨Éè×Ô½âѹµµ°¸¡¢·Ö¾íѹËõºÍÎļþ»Ö¸´µÈ¡£¡£¡£¡£¡£¡£¡£WinRAR½çÃæ¾«Á·£¬£¬£¬£¬ £¬£¬£¬²Ù×÷Àû±ã£¬£¬£¬£¬ £¬£¬£¬ÊÊÓÃÓÚWindows¡¢MacºÍLinuxµÈ¶à¸öƽ̨¡£¡£¡£¡£¡£¡£¡£ËüµÄѹËõ±ÈÂʸߣ¬£¬£¬£¬ £¬£¬£¬ÓÈÆäÊÊÓÃÓÚ´óÐÍÎļþºÍÎļþ¼ÐµÄ´¦Öóͷ£¡£¡£¡£¡£¡£¡£¡£WinRAR»¹¾ß±¸Ç¿Ê¢µÄÎļþÖÎÀí¹¦Ð§£¬£¬£¬£¬ £¬£¬£¬Ö§³ÖÍϷŲÙ×÷£¬£¬£¬£¬ £¬£¬£¬ÆÕ±éÓ¦ÓÃÓÚСÎÒ˽¼ÒºÍÆóÒµµÄÊý¾Ý´æ´¢Óë´«Êä¡£¡£¡£¡£¡£¡£¡£


2025Äê6ÔÂ25ÈÕ£¬£¬£¬£¬ £¬£¬£¬°ÙÀÖ²©¼¯ÍÅVSRC¼à²âµ½WinRAR±£´æ±£´æÂ·¾¶´¦Öóͷ£Îó²î£¬£¬£¬£¬ £¬£¬£¬¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÔÊÐíÔ¶³Ì¹¥»÷ÕßÔÚÊÜÓ°ÏìµÄWinRAR°æ±¾ÉÏÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬ £¬£¬£¬ÇÒÐèÓû§½»»¥£¬£¬£¬£¬ £¬£¬£¬¹¥»÷ÕßÐèÓÕʹÓû§»á¼û¶ñÒâÒ³Ãæ»ò·­¿ª¶ñÒâÎļþ¡£¡£¡£¡£¡£¡£¡£Îó²îµÄ»ù´¡Ôµ¹ÊÔ­ÓÉÔÚÓÚWinRAR¶ÔÎļþ·¾¶µÄ´¦Öóͷ£²»µ±£¬£¬£¬£¬ £¬£¬£¬¶ñÒâ½á¹¹µÄÎļþ·¾¶¿ÉÄܵ¼ÖÂÀú³Ì»á¼û²»Ó¦»á¼ûµÄĿ¼£¬£¬£¬£¬ £¬£¬£¬´Ó¶øÔÚÄ¿½ñÓû§ÉÏÏÂÎÄÖÐÖ´ÐжñÒâ´úÂ룬£¬£¬£¬ £¬£¬£¬Îó²îÆÀ·Ö7.8·Ö£¬£¬£¬£¬ £¬£¬£¬Îó²îÆ·¼¶¸ßΣ¡£¡£¡£¡£¡£¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


WinRAR ¡Ü 7.11


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


WinRAR ÒÑÐû²¼ÐÞ¸´°æ±¾£¬£¬£¬£¬ £¬£¬£¬½¨ÒéÊÜÓ°ÏìÓû§¾¡¿ìÉý¼¶ÖÁ WinRAR ¡Ý 7.12 Beta 1


ÏÂÔØÁ´½Ó£º

https://www.win-rar.com/singlenewsview.html?&tx_ttnews%5Btt_news%5D=276&cHash=388885bd3908a40726f535c026f94eb6/


3.2 ÔÝʱ²½·¥


ÔÝÎÞ¡£¡£¡£¡£¡£¡£¡£


3.3 ͨÓý¨Òé


?°´ÆÚ¸üÐÂϵͳ²¹¶¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬ £¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬£¬£¬ £¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£¡£¡£
?ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬ £¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬ £¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬ £¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬ £¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£¡£¡£¡£¡£
?ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬ £¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£¡£¡£
?ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬ £¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬£¬£¬ £¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£¡£¡£
?ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://www.zerodayinitiative.com/advisories/ZDI-25-409/
https://www.win-rar.com/singlenewsview.html?&tx_ttnews%5Btt_news%5D=276&cHash=388885bd3908a40726f535c026f94eb6
https://nvd.nist.gov/vuln/detail/CVE-2025-6218