¡¾Îó²îͨ¸æ¡¿WinRARÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-35052£©
Ðû²¼Ê±¼ä 2021-10-220x00 Îó²î¸ÅÊö
CVE ID | CVE-2021-35052 | ʱ ¼ä | 2021-10-20 |
Àà ÐÍ | RCE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | WinRAR 5.70 |
¹¥»÷ÖØÆ¯ºó | ¿ÉÓÃÐÔ | ||
Óû§½»»¥ | ËùÐèȨÏÞ | ||
PoC/EXP | ÔÚҰʹÓà |
0x01 Îó²îÏêÇé

WinRARÊÇÒ»¿î¹¦Ð§Ç¿Ê¢µÄѹËõ°ü¹ÜÀíÆ÷£¬£¬£¬¿ÉÒÔʹÓÃËü½¨ÉèÏ¢Õùѹ³£¼ûµÄѹËõ°üÃûÌ㬣¬£¬Èç RAR ºÍ ZIPµÈÀàÐÍ¡£¡£¡£¡£
2021 Äê 10 Ô 20 ÈÕ£¬£¬£¬WinRAR WindowsÊÔÓðæ5.70±»¹ûÕæÅû¶¿ÉÄܱ£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-35052£©£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ý×èµ²ºÍÐ޸ķ¢Ë͸øÓ¦ÓóÌÐòÓû§µÄÇëÇ󣬣¬£¬×îÖÕʵÏÖÔÚÊܺ¦ÕßµÄÅÌËã»úÉÏÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£

¶Ô¸ÃÎó²îµÄÑо¿Ô´ÓÚMSHTML£¨ÓÖÃûTrident£©Ëù·ºÆðµÄJavaScript¹ýʧ£¬£¬£¬MSHTMLÊÇÏÖÔÚÒÑÍ£ÓõÄInternet ExplorerµÄרÓÐä¯ÀÀÆ÷ÒýÇæ£¬£¬£¬ÔÚOfficeÖÐÓÃÓÚ·ºÆðWord¡¢ExcelºÍPowerPointÎĵµÖеÄwebÄÚÈÝ£¬£¬£¬´Ó¶ø·¢Ã÷ÔÚÊÔÓÃÆÚÂúºóÆô¶¯Ó¦ÓóÌÐòʱ£¬£¬£¬¹ýʧ´°¿ÚÿÈý´ÎÏÔʾһ´Î¡£¡£¡£¡£
ͨ¹ý×èµ²WinRARͨ¹ý notifier.rarlab[.com]ÌáÐÑÓû§Ãâ·ÑÊÔÓÃÆÚ¿¢ÊÂʱ·¢Ë͵ÄÏìÓ¦´úÂ룬£¬£¬²¢½«ÆäÐÞ¸ÄΪ¡°301 Moved Permanently¡± ÖØ¶¨ÏòÐÂÎÅ£¬£¬£¬¸ÃÎó²î¿ÉÒÔ±»ÀÄÓÃÀ´ÎªËùÓкóÐøÇëÇ󻺴æÖض¨Ïòµ½¹¥»÷Õß¿ØÖƵĶñÒâÓò¡£¡£¡£¡£³ý´ËÖ®Í⣬£¬£¬ÒѾÄܹ»»á¼ûÍ³Ò»ÍøÂçÓòµÄ¹¥»÷Õß¿ÉÒÔÖ´ÐÐARPÓÕÆ¹¥»÷£¬£¬£¬ÒÔÔ¶³ÌÆô¶¯Ó¦ÓóÌÐò¡¢¼ìË÷µ±ÌïÖ÷»úÐÅÏ¢£¬£¬£¬ÉõÖÁÔËÐÐí§Òâ´úÂë¡£¡£¡£¡£
Ó°Ïì¹æÄ£
WinRAR Windows 5.70ÊÔÓðæ
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚÎó²îÒѾ¹ûÕæÅû¶£¬£¬£¬½¨ÒéÊÜÓ°ÏìµÄÓû§Ê¹Óùٷ½¸¶·Ñ°æ±¾¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
http://www.winrar.com.cn/
0x03 ²Î¿¼Á´½Ó
https://swarm.ptsecurity.com/winrars-vulnerable-trialware-when-free-software-isnt-free/
https://thehackernews.com/2021/10/bug-in-free-winrar-software-could-let.html
https://securityaffairs.co/wordpress/123652/hacking/winrar-trial-flaw.html?utm_source=rss&utm_medium=rss&utm_campaign=winrar-trial-flaw
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2021-10-22 | Ê×´ÎÐû²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
CVSS£ºwww.first.org
NVD£ºnvd.nist.gov
0x06 ¹ØÓÚc7c7ÓéÀÖÆ½Ì¨
¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º



¾©¹«Íø°²±¸11010802024551ºÅ