¡¾·ì϶¹«¸æ¡¿WinRARÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-35052£©
°ä²¼¹¦·ò 2021-10-220x00 ·ì϶¸ÅÊö
CVE ID | CVE-2021-35052 | ʱ ¼ä | 2021-10-20 |
Àà ÐÍ | RCE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | WinRAR 5.70 |
¹¥»÷¸´ÔÓ¶È | ¿ÉÓÃÐÔ | ||
Óû§½»»¥ | ËùÐèȨÏÞ | ||
PoC/EXP | ÔÚÒ°ÀûÓÃ |
0x01 ·ì϶ÏêÇé

WinRARÊÇÒ»¿îÖ°ÄÜ׳´óµÄѹËõ°üÖÎÀíÆ÷£¬Äܹ»Ê¹ÓÃËü´´½¨ºÍ½âѹ³£¼ûµÄѹËõ°üÌåʽ£¬Èç RAR ºÍ ZIPµÈÀàÐÍ¡£
2021 Äê 10 Ô 20 ÈÕ£¬WinRAR WindowsÊÔÓðæ5.70±»¹«¿ªÅû¶¿ÉÄÜ´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-35052£©£¬Ô¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ýÀ¹½ØºÍÅú¸Ä·¢Ë͸øÀûÓ÷¨Ê½Óû§µÄÒªÇó£¬×îÖÕʵ´Ë¿ÌÊܺ¦ÕßµÄÍÆËã»úÉÏÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£

¶Ô¸Ã·ì϶µÄ×êÑÐÔ´ÓÚMSHTML£¨±ðÃûTrident£©Ëù³öÏÖµÄJavaScriptÃýÎó£¬MSHTMLÊÇĿǰÒÑÍ£ÓõÄInternet ExplorerµÄרÓÐä¯ÀÀÆ÷ÒýÇæ£¬ÔÚOfficeÖÐÓÃÓÚ³öÏÖWord¡¢ExcelºÍPowerPointÎĵµÖеÄwebÄÚÈÝ£¬´Ó¶ø·¢´Ë¿ÌÊÔÓÃÆÚÂúºóÆô¶¯ÀûÓ÷¨Ê½Ê±£¬ÃýÎó´°¿ÚÿÈý´ÎÏÔʾһ´Î¡£
ͨ¹ýÀ¹½ØWinRARͨ¹ý notifier.rarlab[.com]ÌáÐÑÓû§Ãâ·ÑÊÔÓÃÆÚʵÏÖʱ·¢Ë͵ÄÏìÓ¦´úÂ룬²¢½«ÆäÅú¸ÄΪ¡°301 Moved Permanently¡± ³Á¶¨ÏòÐÂÎÅ£¬¸Ã·ì϶Äܹ»±»ÀÄÓÃÀ´ÎªËùÓкóÐøÒªÇ󻺴æ³Á¶¨Ïòµ½¹¥»÷Õß½ÚÔìµÄ¶ñÒâÓò¡£³ý´ËÖ®±í£¬ÒѾ¿ÉÄܽӼûÍ³Ò»ÍøÂçÓòµÄ¹¥»÷ÕßÄܹ»Ö´ÐÐARPºýŪ¹¥»÷£¬ÒÔÔ¶³ÌÆô¶¯ÀûÓ÷¨Ê½¡¢¼ìË÷±¾µØÖ÷»úÐÅÏ¢£¬ÉõÖÁÔËÐÐËÁÒâ´úÂë¡£
Ó°ÏìÁìÓò
WinRAR Windows 5.70ÊÔÓðæ
0x02 ´ëÖý¨Òé
Ŀǰ·ì϶ÒѾ¹«¿ªÅû¶£¬½¨ÒéÊÜÓ°ÏìµÄÓû§Ê¹Óùٷ½¸¶·Ñ°æ±¾¡£
ÏÂÔØÁ´½Ó£º
http://www.winrar.com.cn/
0x03 ²Î¿¼Á´½Ó
https://swarm.ptsecurity.com/winrars-vulnerable-trialware-when-free-software-isnt-free/
https://thehackernews.com/2021/10/bug-in-free-winrar-software-could-let.html
https://securityaffairs.co/wordpress/123652/hacking/winrar-trial-flaw.html?utm_source=rss&utm_medium=rss&utm_campaign=winrar-trial-flaw
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | Åú¸ÄÄÚÈÝ |
V1.0 | 2021-10-22 | ³õ´Î°ä²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
CVSS£ºwww.first.org
NVD£ºnvd.nist.gov
0x06 ¹ØÓÚGA»Æ½ð¼×
¹Ø×¢ÒÔϹ«¼ÒºÅ£¬»ñÈ¡¸ü¶à×ÊѶ£º



¾©¹«Íø°²±¸11010802024551ºÅ