¡¾·ì϶¹«¸æ¡¿WinRARÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-35052£©

°ä²¼¹¦·ò 2021-10-22

0x00 ·ì϶¸ÅÊö

CVE     ID

CVE-2021-35052

ʱ      ¼ä

2021-10-20

Àà      ÐÍ

RCE

µÈ      ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

WinRAR 5.70

¹¥»÷¸´ÔÓ¶È


¿ÉÓÃÐÔ


Óû§½»»¥


ËùÐèȨÏÞ


PoC/EXP


ÔÚÒ°ÀûÓÃ


 

0x01 ·ì϶ÏêÇé

image.png

WinRARÊÇÒ»¿îÖ°ÄÜ׳´óµÄѹËõ°üÖÎÀíÆ÷ £¬Äܹ»Ê¹ÓÃËü´´½¨ºÍ½âѹ³£¼ûµÄѹËõ°üÌåʽ £¬Èç RAR ºÍ ZIPµÈÀàÐÍ¡£

2021 Äê 10 Ô 20 ÈÕ £¬WinRAR WindowsÊÔÓðæ5.70±»¹«¿ªÅû¶¿ÉÄÜ´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-35052£© £¬Ô¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ýÀ¹½ØºÍÅú¸Ä·¢Ë͸øÀûÓ÷¨Ê½Óû§µÄÒªÇó £¬×îÖÕʵ´Ë¿ÌÊܺ¦ÕßµÄÍÆËã»úÉÏÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£

image.png

¶Ô¸Ã·ì϶µÄ×êÑÐÔ´ÓÚMSHTML£¨±ðÃûTrident£©Ëù³öÏÖµÄJavaScriptÃýÎó £¬MSHTMLÊÇĿǰÒÑÍ£ÓõÄInternet ExplorerµÄרÓÐä¯ÀÀÆ÷ÒýÇæ £¬ÔÚOfficeÖÐÓÃÓÚ³öÏÖWord¡¢ExcelºÍPowerPointÎĵµÖеÄwebÄÚÈÝ £¬´Ó¶ø·¢´Ë¿ÌÊÔÓÃÆÚÂúºóÆô¶¯ÀûÓ÷¨Ê½Ê± £¬ÃýÎó´°¿ÚÿÈý´ÎÏÔʾһ´Î¡£

ͨ¹ýÀ¹½ØWinRARͨ¹ý notifier.rarlab[.com]ÌáÐÑÓû§Ãâ·ÑÊÔÓÃÆÚʵÏÖʱ·¢Ë͵ÄÏìÓ¦´úÂë £¬²¢½«ÆäÅú¸ÄΪ¡°301 Moved Permanently¡± ³Á¶¨ÏòÐÂÎÅ £¬¸Ã·ì϶Äܹ»±»ÀÄÓÃÀ´ÎªËùÓкóÐøÒªÇ󻺴æ³Á¶¨Ïòµ½¹¥»÷Õß½ÚÔìµÄ¶ñÒâÓò¡£³ý´ËÖ®±í £¬ÒѾ­¿ÉÄܽӼûÍ³Ò»ÍøÂçÓòµÄ¹¥»÷ÕßÄܹ»Ö´ÐÐARPºýŪ¹¥»÷ £¬ÒÔÔ¶³ÌÆô¶¯ÀûÓ÷¨Ê½¡¢¼ìË÷±¾µØÖ÷»úÐÅÏ¢ £¬ÉõÖÁÔËÐÐËÁÒâ´úÂë¡£

 

Ó°ÏìÁìÓò

WinRAR Windows 5.70ÊÔÓðæ

 

0x02 ´ëÖý¨Òé

Ŀǰ·ì϶ÒѾ­¹«¿ªÅû¶ £¬½¨ÒéÊÜÓ°ÏìµÄÓû§Ê¹Óùٷ½¸¶·Ñ°æ±¾¡£

ÏÂÔØÁ´½Ó£º

http://www.winrar.com.cn/

 

0x03 ²Î¿¼Á´½Ó

https://swarm.ptsecurity.com/winrars-vulnerable-trialware-when-free-software-isnt-free/

https://thehackernews.com/2021/10/bug-in-free-winrar-software-could-let.html

https://securityaffairs.co/wordpress/123652/hacking/winrar-trial-flaw.html?utm_source=rss&utm_medium=rss&utm_campaign=winrar-trial-flaw

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

Åú¸ÄÄÚÈÝ

V1.0

2021-10-22

³õ´Î°ä²¼

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

CVSS£ºwww.first.org

NVD£ºnvd.nist.gov

 

0x06 ¹ØÓÚGA»Æ½ð¼×

¹Ø×¢ÒÔϹ«¼ÒºÅ £¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png