¡¾Îó²îͨ¸æ¡¿WinRARÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-35052£©

Ðû²¼Ê±¼ä 2021-10-22

0x00 Îó²î¸ÅÊö

CVE     ID

CVE-2021-35052

ʱ      ¼ä

2021-10-20

Àà      ÐÍ

RCE

µÈ      ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

WinRAR 5.70

¹¥»÷ÖØÆ¯ºó


¿ÉÓÃÐÔ


Óû§½»»¥


ËùÐèȨÏÞ


PoC/EXP


ÔÚҰʹÓÃ


 

0x01 Îó²îÏêÇé

image.png

WinRARÊÇÒ»¿î¹¦Ð§Ç¿Ê¢µÄѹËõ°ü¹ÜÀíÆ÷£¬£¬ £¬¿ÉÒÔʹÓÃËü½¨ÉèÏ¢Õùѹ³£¼ûµÄѹËõ°üÃûÌ㬣¬ £¬Èç RAR ºÍ ZIPµÈÀàÐÍ¡£¡£ ¡£¡£

2021 Äê 10 Ô 20 ÈÕ£¬£¬ £¬WinRAR WindowsÊÔÓðæ5.70±»¹ûÕæÅû¶¿ÉÄܱ£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-35052£©£¬£¬ £¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ý×èµ²ºÍÐ޸ķ¢Ë͸øÓ¦ÓóÌÐòÓû§µÄÇëÇ󣬣¬ £¬×îÖÕʵÏÖÔÚÊܺ¦ÕßµÄÅÌËã»úÉÏÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£ ¡£¡£

image.png

¶Ô¸ÃÎó²îµÄÑо¿Ô´ÓÚMSHTML£¨ÓÖÃûTrident£©Ëù·ºÆðµÄJavaScript¹ýʧ£¬£¬ £¬MSHTMLÊÇÏÖÔÚÒÑÍ£ÓõÄInternet ExplorerµÄרÓÐä¯ÀÀÆ÷ÒýÇæ£¬£¬ £¬ÔÚOfficeÖÐÓÃÓÚ·ºÆðWord¡¢ExcelºÍPowerPointÎĵµÖеÄwebÄÚÈÝ£¬£¬ £¬´Ó¶ø·¢Ã÷ÔÚÊÔÓÃÆÚÂúºóÆô¶¯Ó¦ÓóÌÐòʱ£¬£¬ £¬¹ýʧ´°¿ÚÿÈý´ÎÏÔʾһ´Î¡£¡£ ¡£¡£

ͨ¹ý×èµ²WinRARͨ¹ý notifier.rarlab[.com]ÌáÐÑÓû§Ãâ·ÑÊÔÓÃÆÚ¿¢ÊÂʱ·¢Ë͵ÄÏìÓ¦´úÂ룬£¬ £¬²¢½«ÆäÐÞ¸ÄΪ¡°301 Moved Permanently¡± ÖØ¶¨ÏòÐÂÎÅ£¬£¬ £¬¸ÃÎó²î¿ÉÒÔ±»ÀÄÓÃÀ´ÎªËùÓкóÐøÇëÇ󻺴æÖض¨Ïòµ½¹¥»÷Õß¿ØÖƵĶñÒâÓò¡£¡£ ¡£¡£³ý´ËÖ®Í⣬£¬ £¬ÒѾ­Äܹ»»á¼ûÍ³Ò»ÍøÂçÓòµÄ¹¥»÷Õß¿ÉÒÔÖ´ÐÐARPÓÕÆ­¹¥»÷£¬£¬ £¬ÒÔÔ¶³ÌÆô¶¯Ó¦ÓóÌÐò¡¢¼ìË÷µ±ÌïÖ÷»úÐÅÏ¢£¬£¬ £¬ÉõÖÁÔËÐÐí§Òâ´úÂë¡£¡£ ¡£¡£

 

Ó°Ïì¹æÄ£

WinRAR Windows 5.70ÊÔÓðæ

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚÎó²îÒѾ­¹ûÕæÅû¶£¬£¬ £¬½¨ÒéÊÜÓ°ÏìµÄÓû§Ê¹Óùٷ½¸¶·Ñ°æ±¾¡£¡£ ¡£¡£

ÏÂÔØÁ´½Ó£º

http://www.winrar.com.cn/

 

0x03 ²Î¿¼Á´½Ó

https://swarm.ptsecurity.com/winrars-vulnerable-trialware-when-free-software-isnt-free/

https://thehackernews.com/2021/10/bug-in-free-winrar-software-could-let.html

https://securityaffairs.co/wordpress/123652/hacking/winrar-trial-flaw.html?utm_source=rss&utm_medium=rss&utm_campaign=winrar-trial-flaw

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2021-10-22

Ê×´ÎÐû²¼

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

CVSS£ºwww.first.org

NVD£ºnvd.nist.gov

 

0x06 ¹ØÓÚc7c7ÓéÀÖÆ½Ì¨

¹Ø×¢ÒÔϹ«Öںţ¬£¬ £¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png