Skip to content
KitploitKITPLOIT
ツールエクスプロイトブログ
Log in
提出
ツールエクスプロイトブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

フィードお問い合わせプライバシー© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
CVE-2025-6218-WinRAR-RCE-POC — CVE-2025-6218 - WinRARパストラバーサルRCE脆弱性(バージョン7.11以前に影響)の包括的な分析と概念実証 | Kitploit
ツール/GitHubGitHub/chrxstxqn/cve-2025-6218-winrar-rce-poc
フィッシングツール永続化メカニズム脆弱性分析エクスプロイト横移動マルウェア分析ペネトレーションテスト学習と教育バイナリエクスプロイト

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
GitHubchrxstxqn/cve-2025-6218-winrar-rce-poc

CVE-2025-6218-WinRAR-RCE-POC

CVE-2025-6218 - WinRARパストラバーサルRCE脆弱性(バージョン7.11以前に影響)の包括的な分析と概念実証

リポジトリを見る
21199ヶ月前未レビュー

CVE-2025-6218: WinRAR パストラバーサル RCE

CVE CVSS Score Platform License Status

⚠️ 重大な脆弱性 - 積極的な悪用が確認されました

CVE-2025-6218 は、WinRAR におけるパストラバーサルの深刻な脆弱性で、任意のコード実行を可能にします。現在、APT グループ(GOFFEE、Bitter(APT-C-08)、Gamaredon など)によって悪用されています。


📋 目次

  • 概要
  • 技術的説明
  • エクスプロイトの仕組み
  • 影響を受けるバージョン
  • 攻撃シナリオ
  • 脅威アクター
  • 概念実証
  • 検出とIOC
  • 緩和策
  • タイムライン
  • リポジトリ構成
  • 参考情報

🎯 概要

CVE-2025-6218 は、Windows 版 WinRAR における深刻なパストラバーサルの脆弱性であり、攻撃者に任意のコード実行を許します。

主な影響

項目詳細
CVSS スコア7.8(高)
影響を受けるバージョンWinRAR ≤ 7.11(Windows のみ)
対象プラットフォームWindows 10、11、Server
影響を受けるユーザー数約5億人
修正版WinRAR 7.12(2025年6月)
ステータス🔴 現在も悪用中
CISA KEV2025年12月9日追加

なぜ危険なのか?

攻撃者は以下のことが可能です:

  • ✅ 機密フォルダ(スタートアップ、System32)にファイルを配置
  • ✅ システム起動時にコードを実行
  • ✅ 高い権限なしで永続性を確立
  • ✅ アンチウイルスを回避(正規ツールの悪用)
  • ✅ 企業ネットワークでのラテラルムーブメント

🔍 技術的説明

脆弱性の概要

WinRAR は、特殊な .rar アーカイブ内のファイルパスを正しく検証しません。ユーザーが不正なアーカイブを展開すると、パストラバーサル(../ または ..\\)シーケンスを使用して、想定された展開先フォルダの外の任意のパスにファイルが書き込まれる可能性があります。

根本原因 - バグ```c

// Pseudocodice - WinRAR v7.11 (VULNERABILE) void extract_file(rar_entry *entry, char *dest_dir) { char final_path[MAX_PATH];

strcpy(final_path, dest_dir);         // "C:\\Temp\\"
strcat(final_path, entry->filename);  // + "..\\..\\..\\Windows\\System32\\malware.exe"

// ❌ ERRORE: Nessuna validazione del path traversal!
// final_path = "C:\\Temp\\..\\..\\..\\Windows\\System32\\malware.exe"
// Risolto come: "C:\\Windows\\System32\\malware.exe" ← EXPLOIT!

create_file(final_path);  // File creato in directory non intesa

}

### v7.11 で欠けている保護

- ❌ ファイルが `dest_dir` 内に残っているかどうかのチェックがない
- ❌ `..` や `.` シーケンスに対するフィルタがない
- ❌ パスの正規化がない
- ❌ 許可されたディレクトリのホワイトリストがない
- ❌ コンテインメントの検証がない

### v7.12 での修正```c
// WinRAR v7.12 (PATCHED)
bool is_path_contained(char *path, char *base_dir) {
    char canonical[MAX_PATH], canonical_base[MAX_PATH];
    
    // Normalizza entrambi i percorsi
    GetFullPathName(path, MAX_PATH, canonical, NULL);
    GetFullPathName(base_dir, MAX_PATH, canonical_base, NULL);
    
    // Verifica contenimento
    if (strncmp(canonical, canonical_base, strlen(canonical_base)) != 0) {
        return false;  // Path esce dalla directory base
    }
    return true;
}

void extract_file_safe(rar_entry *entry, char *dest_dir) {
    char final_path[MAX_PATH];
    strcpy(final_path, dest_dir);
    strcat(final_path, entry->filename);
    
    // ✅ FIX: Verifica che il file rimane dentro dest_dir
    if (!is_path_contained(final_path, dest_dir)) {
        skip_extraction();  // Rifiuta estrazione
        log_error("Path traversal detected!");
        return;
    }
    
    create_file(final_path);  // Adesso sicuro
}

💥 エクスプロイトの仕組み

パストラバーサルの説明```

Cartella di Estrazione: C:\Temp\Extract

Path nel RAR (craft): ..\..\..\..\Users\\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\payload.bat

Risoluzione Path: C:\Temp\Extract\.. = C:\Temp\ C:\Temp\.. = C:\ C:\.. = C:\ (non può andare oltre)

  • Users\\...\Startup\payload.bat

= C:\Users\\AppData\Roaming\...\Startup\payload.bat ✓

### 攻撃フロー図```
┌─────────────────────────────────────────────┐
│  1. Attaccante crea RAR con path craft     │
│     es: ..\\..\\..\\Startup\\malware.bat   │
└─────────────────────────────────────────────┘
                    ↓
┌─────────────────────────────────────────────┐
│  2. Distribuzione via spear-phishing        │
│     Email mirata con allegato RAR          │
└─────────────────────────────────────────────┘
                    ↓
┌─────────────────────────────────────────────┐
│  3. Vittima estrae archivio con WinRAR     │
│     (versione ≤ 7.11)                       │
└─────────────────────────────────────────────┘
                    ↓
┌─────────────────────────────────────────────┐
│  4. WinRAR non valida path traversal       │
│     File estratto in Startup folder         │
└─────────────────────────────────────────────┘
                    ↓
┌─────────────────────────────────────────────┐
│  5. Al boot: payload eseguito              │
│     RAT stabilisce C2 connection            │
└─────────────────────────────────────────────┘

🔴 脆弱なバージョン

互換性テーブル

バージョンステータス注記
≤ 7.10🔴 脆弱すべてのエクスプロイトが動作します
7.11🔴 脆弱最後の脆弱バージョン
7.12 Beta 1+🟢 修正済みパストラバーサルを修正
7.12+🟢 修正済み修正を含む安定リリース
UNIX / Android✅ 影響なしWindows以外のバージョンは影響を受けません

あなたのバージョンを確認する方法```powershell

Metodo 1: PowerShell

(Get-Item "C:\Program Files\WinRAR\WinRAR.exe").VersionInfo.FileVersion

Output:

7.11.0.0 → 🔴 VULNERABILE ⚠️

7.12.0.0 → 🟢 SAFE ✓

Metodo 2: CMD

wmic datafile where name="C:\\Program Files\\WinRAR\\WinRAR.exe" get Version

Metodo 3: GUI

WinRAR → Help → About WinRAR → Verifica versione

---

## 🌍 攻撃シナリオ

### シナリオ 1: Bitter/APT-C-08 スピアフィッシング(アクティブ確認済み)

**対象**: 政府、軍事組織、戦略機関```
Email Phishing:
  From: [email protected]
  Subject: "Provision of Information for Sectoral for AJK.rar"
  Attachment: Provision_of_Information.rar

Contenuto Archive:
  ├── Document.docx (esca legittima - report convincente)
  └── ..\\..\\..\\..\\Users\\User\\AppData\\Roaming\\Microsoft\\Office\\STARTUP\\Template.dotm
      (macro malato nascosto)

Esecuzione:
  1. Vittima estrae RAR
  2. WinRAR non valida path → Template.dotm finisce in Office STARTUP
  3. Prossimo avvio Word → Macro eseguita automaticamente
  4. PowerShell downloader attivato
  5. C# Trojan scaricato: WmRAT, MiyaRAT, ZxxZ
  6. C2 Server: johnfashionaccess.com
  7. Capabilities:
     - Keylogging
     - Screenshot capture
     - RDP credential stealing
     - File exfiltration
     - Lateral movement

シナリオ2: GOFFEE マルチステージペイロード

目標: ロシア政府機関``` RAR specializzato: ├── run.bat (path: ..\..\..\..\Windows\Startup\run.bat) └── legitimate_document.pdf (esca)

Attack Chain:

  1. Estrazione RAR → run.bat finisce in Startup
  2. Al prossimo boot → run.bat eseguito
  3. PowerShell script scarica stage 2
  4. C# Custom Trojan installato
  5. RAT stabilisce C2 persistente
  6. Full system control achieved
### シナリオ3: ランサムウェア配信```
RAR Weaponized:
  └── locker.exe (path: ..\\..\\..\\Startup\\locker.exe)

Infezione:
  1. Estrazione RAR
  2. locker.exe → Startup folder
  3. Sistema reboota (naturale o forzato)
  4. locker.exe eseguito con diritti user
  5. File system encryption
  6. Ransom note displayed
  7. Bitcoin payment richiesto

🎭 脅威アクター

GOFFEE (Paper Werewolf) 🇷🇺

  • 出身: ロシア
  • 初確認: 2025年7月
  • 標的: ロシア政府機関
  • 手法: CVE-2025-6218 + CVE-2025-8088 (NTFS ADS)
  • ペイロード: C# カスタムトロイの木馬
  • TTP: マルチステージ感染、NTFS ADS悪用

Bitter / APT-C-08 / Manlinghua 🇵🇰

  • 出身: 南アジア
  • 初確認: 2025年8月
  • 標的: 政府、軍事、戦略組織
  • 手法: RAR + マクロテンプレートを用いたスピアフィッシング
  • ペイロード: WmRAT、MiyaRAT、ZxxZ
  • C2: johnfashionaccess.com
  • TTP: ソーシャルエンジニアリング、Officeマクロ悪用
  • ステータス: 🔴 アクティブキャンペーン

Gamaredon 🇷🇺

  • 出身: ロシア (FSBと連携するAPT)
  • 初確認: 2025年11月
  • 標的: ウクライナ政府
  • ペイロード: GamaWiper (データ破壊)
  • タイプ: サイバーサボタージュ + 諜報活動
  • TTP: 大量配布、ワイパー展開

🧪 概念実証

ツールをダウンロード