
CVE-2025-6218 के लिए व्यापक विश्लेषण और प्रूफ-ऑफ-कॉन्सेप्ट - WinRAR पथ ट्रैवर्सल RCE भेद्यता जो संस्करण 7.11 और उससे पहले के संस्करणों को प्रभावित करती है
⚠️ गंभीर कमजोरी - सक्रिय शोषण की पुष्टि
CVE-2025-6218 WinRAR में एक गंभीर पथ ट्रैवर्सल कमजोरी है जो मनमाना कोड निष्पादन की अनुमति देती है। वर्तमान में APT समूहों जैसे GOFFEE, Bitter (APT-C-08) और Gamaredon द्वारा शोषित।
CVE-2025-6218 Windows के लिए WinRAR में एक गंभीर पथ ट्रैवर्सल कमजोरी है जो हमलावरों को मनमाना कोड निष्पादित करने की अनुमति देती है।
| पहलू | विवरण |
|---|---|
| CVSS Score | 7.8 (High) |
| कमजोर संस्करण | WinRAR ≤ 7.11 (Windows only) |
| प्लेटफॉर्म | Windows 10, 11, Server |
| प्रभावित उपयोगकर्ता | ~500 मिलियन |
| पैच किया गया | WinRAR 7.12 (जून 2025) |
| स्थिति | 🔴 सक्रिय शोषण |
| CISA KEV | 9 दिसंबर 2025 को जोड़ा गया |
एक हमलावर कर सकता है:
WinRAR विशेष .rar संग्रहों के अंदर फ़ाइल पथों को सही ढंग से मान्य नहीं करता है। जब कोई उपयोगकर्ता एक दूषित संग्रह निकालता है, तो फ़ाइलें पथ ट्रैवर्सल अनुक्रमों (../ या ..\\) का उपयोग करके इच्छित निष्कर्षण फ़ोल्डर के बाहर मनमाने पथों पर लिखी जा सकती हैं।
// Pseudocodice - WinRAR v7.11 (VULNERABILE) void extract_file(rar_entry *entry, char *dest_dir) { char final_path[MAX_PATH];
strcpy(final_path, dest_dir); // "C:\\Temp\\"
strcat(final_path, entry->filename); // + "..\\..\\..\\Windows\\System32\\malware.exe"
// ❌ ERRORE: Nessuna validazione del path traversal!
// final_path = "C:\\Temp\\..\\..\\..\\Windows\\System32\\malware.exe"
// Risolto come: "C:\\Windows\\System32\\malware.exe" ← EXPLOIT!
create_file(final_path); // File creato in directory non intesa
}
### v7.11 में अनुपस्थित सुरक्षाएँ
- ❌ कोई जाँच नहीं कि फ़ाइल `dest_dir` के अंदर रहती है या नहीं
- ❌ `..` या `.` अनुक्रमों पर कोई फ़िल्टर नहीं
- ❌ पथों का कोई सामान्यीकरण नहीं
- ❌ अनुमत निर्देशिकाओं की कोई श्वेतसूची नहीं
- ❌ संयोजन (containment) का कोई सत्यापन नहीं
### v7.12 में सुधार```c
// WinRAR v7.12 (PATCHED)
bool is_path_contained(char *path, char *base_dir) {
char canonical[MAX_PATH], canonical_base[MAX_PATH];
// Normalizza entrambi i percorsi
GetFullPathName(path, MAX_PATH, canonical, NULL);
GetFullPathName(base_dir, MAX_PATH, canonical_base, NULL);
// Verifica contenimento
if (strncmp(canonical, canonical_base, strlen(canonical_base)) != 0) {
return false; // Path esce dalla directory base
}
return true;
}
void extract_file_safe(rar_entry *entry, char *dest_dir) {
char final_path[MAX_PATH];
strcpy(final_path, dest_dir);
strcat(final_path, entry->filename);
// ✅ FIX: Verifica che il file rimane dentro dest_dir
if (!is_path_contained(final_path, dest_dir)) {
skip_extraction(); // Rifiuta estrazione
log_error("Path traversal detected!");
return;
}
create_file(final_path); // Adesso sicuro
}
Cartella di Estrazione: C:\Temp\Extract
Path nel RAR (craft): ..\..\..\..\Users\\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\payload.bat
Risoluzione Path: C:\Temp\Extract\.. = C:\Temp\ C:\Temp\.. = C:\ C:\.. = C:\ (non può andare oltre)
= C:\Users\\AppData\Roaming\...\Startup\payload.bat ✓
### आक्रमण प्रवाह आरेख```
┌─────────────────────────────────────────────┐
│ 1. Attaccante crea RAR con path craft │
│ es: ..\\..\\..\\Startup\\malware.bat │
└─────────────────────────────────────────────┘
↓
┌─────────────────────────────────────────────┐
│ 2. Distribuzione via spear-phishing │
│ Email mirata con allegato RAR │
└─────────────────────────────────────────────┘
↓
┌─────────────────────────────────────────────┐
│ 3. Vittima estrae archivio con WinRAR │
│ (versione ≤ 7.11) │
└─────────────────────────────────────────────┘
↓
┌─────────────────────────────────────────────┐
│ 4. WinRAR non valida path traversal │
│ File estratto in Startup folder │
└─────────────────────────────────────────────┘
↓
┌─────────────────────────────────────────────┐
│ 5. Al boot: payload eseguito │
│ RAT stabilisce C2 connection │
└─────────────────────────────────────────────┘
| संस्करण | स्थिति | नोट्स |
|---|---|---|
| ≤ 7.10 | 🔴 कमजोर | सभी एक्सप्लॉइट काम करते हैं |
| 7.11 | 🔴 कमजोर | अंतिम कमजोर संस्करण |
| 7.12 Beta 1+ | 🟢 पैच किया गया | पथ ट्रैवर्सल फिक्स |
| 7.12+ | 🟢 पैच किया गया | फिक्स के साथ स्थिर रिलीज |
| UNIX / Android | ✅ प्रभावित नहीं | गैर-विंडोज संस्करण प्रभावित नहीं |
(Get-Item "C:\Program Files\WinRAR\WinRAR.exe").VersionInfo.FileVersion
wmic datafile where name="C:\\Program Files\\WinRAR\\WinRAR.exe" get Version
## 🌍 हमले के परिदृश्य
### परिदृश्य 1: Bitter/APT-C-08 Spear-Phishing (सक्रिय पुष्टि)
**लक्ष्य**: सरकार, सैन्य संगठन, रणनीतिक संस्थान```
Email Phishing:
From: [email protected]
Subject: "Provision of Information for Sectoral for AJK.rar"
Attachment: Provision_of_Information.rar
Contenuto Archive:
├── Document.docx (esca legittima - report convincente)
└── ..\\..\\..\\..\\Users\\User\\AppData\\Roaming\\Microsoft\\Office\\STARTUP\\Template.dotm
(macro malato nascosto)
Esecuzione:
1. Vittima estrae RAR
2. WinRAR non valida path → Template.dotm finisce in Office STARTUP
3. Prossimo avvio Word → Macro eseguita automaticamente
4. PowerShell downloader attivato
5. C# Trojan scaricato: WmRAT, MiyaRAT, ZxxZ
6. C2 Server: johnfashionaccess.com
7. Capabilities:
- Keylogging
- Screenshot capture
- RDP credential stealing
- File exfiltration
- Lateral movement
लक्ष्य: रूसी सरकारी संगठन``` RAR specializzato: ├── run.bat (path: ..\..\..\..\Windows\Startup\run.bat) └── legitimate_document.pdf (esca)
Attack Chain:
### परिदृश्य 3: रैनसमवेयर वितरण```
RAR Weaponized:
└── locker.exe (path: ..\\..\\..\\Startup\\locker.exe)