¡¾·ì϶¹«¸æ¡¿OpenVPN DCOÇý¶¯·¨Ê½»º³åÇøÒç¶Âí½Å (CVE-2025-50054)

°ä²¼¹¦·ò 2025-06-23

Ò»¡¢·ì϶¸ÅÊö


·ìϼûû³Æ

OpenVPN DCOÇý¶¯·¨Ê½»º³åÇøÒç¶Âí½Å

CVE   ID

CVE-2025-50054

·ì϶ÀàÐÍ

»º³åÇøÒç¶Âí½Å

·¢ÏÖ¹¦·ò

2025-06-23

·ì϶ÆÀ·Ö

9.8

·ì϶µÈ¼¶

ÑϳÁ

¹¥»÷ÏòÁ¿

±¾µØ

ËùÐèȨÏÞ

µÍ

ÀûÓÃÄѶÈ

µÍ

Óû§½»»¥

²»±ØÒª

PoC/EXP

δ¹«¿ª

ÔÚÒ°ÀûÓÃ

δ·¢ÏÖ


OpenVPNÊÇÒ»¿î¿ªÔ´µÄÐé¹¹¸öÈËÍøÂ磨VPN£©Èí¼þ £¬ÀûÓÃSSL/TLSºÍ̸ʵÏÖ¼ÓÃÜͨѶ £¬Ö§³Öµã¶ÔµãºÍÕ¾µãµ½Õ¾µãµÄ°²È«ÏνÓ £¬¿í·ºÀûÓÃÓÚÔ¶³Ì½Ó¼ûºÍÆóÒµÍøÂç¡£ËüÖ§³Ö¶àÖÖÉí·ÝÑéÖ¤·½Ê½ £¬Ô̺¬Ô¤¹²ÏíÃÜÔ¿¡¢Êý×ÖÖ¤ÊéºÍÓû§Ãû/ÃÜÂë×éºÏ¡£Í¨¹ýʹÓÃOpenSSL¼ÓÃܿ⠣¬OpenVPNÌṩ¸ß´ï256λµÄ¼ÓÃÜÇ¿¶È £¬²¢Ö§³ÖÃÀÂúǰÏò±£ÃÜ£¨PFS£©Ö°ÄÜ £¬¼ÓÇ¿Êý¾Ý°²È«ÐÔ¡£OpenVPN¼æÈݶàÖÖ²Ù×÷ϵͳ £¬ÈçWindows¡¢Linux¡¢macOS¡¢iOSºÍAndroid £¬ºÏÓÃÓÚ¼ÒÍ¥Óû§¡¢ÆóÒµºÍ¿ª·¢Õß £¬ÒòÆä¸ß°²È«ÐÔ¡¢½Ã½ÝÐԺͿªÔ´¸öÐÔ £¬³ÉΪȫÇò×îÊÜÓ­½ÓµÄVPN½â¾ö¹æ»®Ö®Ò»¡£


2025Äê6ÔÂ23ÈÕ £¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½openvpn°ä²¼°²È«²¼¸æ £¬Åû¶openvpnÖеÄÒ»¸ö»º³åÇøÒç¶Âí½Å¡£¸Ã·ì϶´æÔÚÓÚOpenVPNµÄWindowsÊý¾ÝÍ¨Â·Ð¶ÔØÇý¶¯·¨Ê½£¨ovpn-dco-win£©ÖÐ £¬µ±Óû§¿Õ¼ä¹ý³ÌÏòÄÚºËÇý¶¯·¨Ê½·¢Ëͳ¬¹ý1500×ֽڵĽÚÔìÐÂÎÅʱ £¬»áµ¼ÖÂWindows DCOÇý¶¯·¨Ê½±ÀÀ£¡£´Ë·ì϶½öÄÜͨ¹ý±¾µØ¹ý³Ì´¥·¢ £¬¶ø·ÇÔ¶³Ì¹¥»÷ £¬ÇÒ¼´±ã³¤¶ÌÌØÈ¨¹ý³ÌÒ²ÄÜÀûÓô˷ì϶¡£OpenVPN×ÔÉíÓµÓÐÏÞ¶È £¬²»»á·¢Ëͳ¬³¤ÐÂÎÅ £¬µ«×Ô½ç˵±àÒëµÄOpenVPN»òÆäËûÓëDCOÇý¶¯·¨Ê½½»»¥µÄ¹ý³Ì¿ÉÄÜÈÆ¹ý¸ÃÏÞ¶È £¬´¥·¢·ì϶¡£¸Ã·ì϶¿ÉÄܵ¼ÖÂϵͳ²»²»±ä¡£


¶þ¡¢Ó°ÏìÁìÓò


ovpn-dco-win ¡Ü 1.3.0
2.6.0-I005 ¡Ü OpenVPN GUI for Windows ¡Ü 2.6.14-I001
OpenVPN GUI for Windows = 2.7_alpha1-I001


Èý¡¢°²È«´ëÊ©


3.1 Éý¼¶°æ±¾


½¨ÒéÉý¼¶OpenVPN GUI for WindowsÖÁÈçϰ汾
OpenVPN GUI for Windows ¡Ý 2.6.14-I002
OpenVPN GUI for Windows ¡Ý 2.7_alpha2-I001¡£


ÏÂÔØÁ´½Ó£ºhttps://openvpn.net/community-downloads/


3.2 һʱ´ëÊ©


ÔÝÎÞ¡£


3.3 ͨÓý¨Òé


?¶¨ÆÚ¸üÐÂϵͳ²¹¶¡ £¬Ï÷¼õϵͳ·ì϶ £¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£
?¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔì £¬Åú¸Ä·À»ðǽսÊõ £¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ £¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø £¬Ï÷¼õ¹¥»÷Ãæ¡£
?ʹÓÃÆóÒµ¼¶°²È«²úÆ· £¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£
?¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí £¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò £¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£
?ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£


3.4 ²Î¿¼Á´½Ó


https://community.openvpn.net/Security%20Announcements/CVE-2025-50054
https://nvd.nist.gov/vuln/detail/CVE-2025-50054