Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | 7-Zip Ŀ¼´©Ô½µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐÎó²î |
CVE ID | CVE-2025-11001 |
Îó²îÀàÐÍ | Ŀ¼´©Ô½ | ·¢Ã÷ʱ¼ä | 2025-10-16 |
Îó²îÆÀ·Ö | 7.0 | Îó²îÆ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍâµØ | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | ¸ß | Óû§½»»¥ | ÐèÒª |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
7-ZipÊÇÒ»¿î¿ªÔ´µÄÎļþѹËõÏ¢ÕùѹËõÈí¼þ£¬£¬£¬£¬£¬£¬£¬Ö§³Ö¶àÖÖÎļþÃûÌ㬣¬£¬£¬£¬£¬£¬°üÀ¨7z¡¢ZIP¡¢RAR¡¢TAR¡¢GZµÈ¡£¡£¡£ËüÒÔ¸ßѹËõ±ÈºÍÇáÓ¯µÄ²Ù×÷½çÃæÖø³Æ£¬£¬£¬£¬£¬£¬£¬Äܹ»ÓÐÓõؼõСÎļþ¾Þϸ£¡£¡£¬£¬£¬£¬£¬£¬£¬Í¬Ê±¼á³ÖÓÅÒìµÄѹËõЧÂÊ¡£¡£¡£7-ZipʹÓÃ×Ô¼ºµÄ7zÃûÌ㬣¬£¬£¬£¬£¬£¬¸ÃÃûÌþßÓиü¸ßµÄѹËõÂÊ£¬£¬£¬£¬£¬£¬£¬²¢Ö§³ÖÇ¿¼ÓÃÜËã·¨¡£¡£¡£7-ZipÖ§³Ö¿çƽ̨²Ù×÷£¬£¬£¬£¬£¬£¬£¬³ýÁËWindows£¬£¬£¬£¬£¬£¬£¬LinuxºÍmacOSÒ²¿ÉÒÔʹÓÃp7zip°æ±¾¡£¡£¡£7-ZipÌṩÁËÏÂÁîÐнçÃæºÍͼÐÎÓû§½çÃæ£¨GUI£©£¬£¬£¬£¬£¬£¬£¬Êʺϲî±ðÓû§µÄÐèÇ󣬣¬£¬£¬£¬£¬£¬ÆÕ±éÓ¦ÓÃÓÚÒ»Ñùƽ³£ÎļþѹËõ¡¢¼ÓÃÜÏ¢ÕùѹÊÂÇéÖС£¡£¡£
2025Äê10ÔÂ16ÈÕ£¬£¬£¬£¬£¬£¬£¬°ÙÀÖ²©¼¯ÍÅVSRC¼à²âµ½Ò»¸öÓ°Ïì7-ZipѹËõ¹¤¾ßµÄĿ¼´©Ô½Îó²î£¨CVE-2025-11001£©£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚZIPÎļþÖзûºÅÁ´½Ó£¨symlink£©µÄ´¦Öóͷ£·½·¨¡£¡£¡£¹¥»÷Õß¿Éͨ¹ý½á¹¹¶ñÒâZIPÎļþ£¬£¬£¬£¬£¬£¬£¬Ê¹ÓøÃĿ¼±éÀúÎó²î£¬£¬£¬£¬£¬£¬£¬µ¼Ö³ÌÐò»á¼ûδ¾ÊÚȨµÄĿ¼²¢Ö´ÐжñÒâ´úÂë¡£¡£¡£Í¬Ê±£¬£¬£¬£¬£¬£¬£¬7-ZipѹËõ¹¤¾ß»¹±£´æÁíÒ»¸öÀàËÆÎó²î£¨CVE-2025-11002£©£¬£¬£¬£¬£¬£¬£¬Á½¸öÎó²î¾ùÔÊÐíÔ¶³Ì¹¥»÷ÕßÔÚÊÜÓ°ÏìµÄϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£Í¨¹ýÌØÖÆµÄZIPÎļþ£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Ê¹Ó÷ûºÅÁ´½Ó´¦Öóͷ£È±ÏÝ£¬£¬£¬£¬£¬£¬£¬´Ùʹ³ÌÐò»á¼û±¾²»Ó¦»á¼ûµÄĿ¼£¬£¬£¬£¬£¬£¬£¬½ø¶øÖ´ÐжñÒâ´úÂë¡£¡£¡£ÕâÁ½¸öÎó²îµÄʹÓ÷½·¨ÏàËÆ£¬£¬£¬£¬£¬£¬£¬¾ù¿Éµ¼ÖÂϵͳÇ徲Σº¦¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
7-Zip < 25.00
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
7-Zip¹Ù·½ÒÑÐû²¼ÐÞ¸´²¹¶¡£¡£¡£¬£¬£¬£¬£¬£¬£¬ÒÔÐÞ¸´¸ÃÎó²î¡£¡£¡£
ÏÂÔØÁ´½Ó£ºhttps://github.com/ip7z/7zip/releases/
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£
3.3 ͨÓý¨Òé
? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¡£¡£¬£¬£¬£¬£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£? ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£? ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£? ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://www.zerodayinitiative.com/advisories/ZDI-25-950/https://www.zerodayinitiative.com/advisories/ZDI-25-949/