Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2025-6218-WinRAR-RCE-POC — CVE-2025-6218에 대한 종합 분석 및 개념 증명 - 버전 7.11 및 이전 버전에 영향을 미치는 WinRAR 경로 탐색 RCE 취약점 | Kitploit
도구/GitHubGitHub/chrxstxqn/cve-2025-6218-winrar-rce-poc
Phishing ToolsPersistence MechanismsVulnerability AnalysisExploitationLateral MovementMalware AnalysisPenetration TestingLearning & EducationBinary Exploitation

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
GitHubchrxstxqn/cve-2025-6218-winrar-rce-poc

CVE-2025-6218-WinRAR-RCE-POC

CVE-2025-6218에 대한 종합 분석 및 개념 증명 - 버전 7.11 및 이전 버전에 영향을 미치는 WinRAR 경로 탐색 RCE 취약점

저장소 보기
21209개월 전아직 검토되지 않음

CVE-2025-6218: WinRAR Path Traversal RCE

CVE CVSS Score Platform License Status

⚠️ 심각한 취약점 - 활성 익스플로잇 확인됨

CVE-2025-6218은 WinRAR의 path traversal 취약점으로, 임의 코드 실행을 허용합니다. 현재 APT 그룹(GOFFEE, Bitter(APT-C-08), Gamaredon)에 의해 악용되고 있습니다.


📋 목차

  • 개요
  • 기술 설명
  • 익스플로잇 메커니즘
  • 취약한 버전
  • 공격 시나리오
  • 위협 행위자
  • Proof of Concept
  • 탐지 및 IOC
  • 완화 조치
  • 타임라인
  • 저장소 구조
  • 참고 자료

🎯 개요

CVE-2025-6218은 Windows용 WinRAR에서 path traversal 취약점으로, 공격자가 임의 코드를 실행할 수 있게 합니다.

주요 영향

항목세부 사항
CVSS 점수7.8 (High)
취약한 버전WinRAR ≤ 7.11 (Windows 전용)
플랫폼Windows 10, 11, Server
영향받는 사용자약 5억 명
패치 버전WinRAR 7.12 (2025년 6월)
상태🔴 활성 악용 중
CISA KEV2025년 12월 9일 추가

왜 위험한가?

공격자는 다음을 수행할 수 있습니다:

  • ✅ 중요한 폴더(Startup, System32)에 파일 배치
  • ✅ 시스템 부팅 시 코드 실행
  • ✅ 높은 권한 없이 지속성 확보
  • ✅ 안티바이러스 우회 (합법적인 도구 악용)
  • ✅ 기업 네트워크에서 측면 이동

🔍 기술 설명

취약점이란?

WinRAR은 특수하게 조작된 .rar 아카이브 내 파일 경로를 올바르게 검증하지 않습니다. 사용자가 변조된 아카이브를 추출하면 path traversal 시퀀스(../ 또는 ..\\)를 사용하여 의도된 추출 폴더 외부의 임의 경로에 파일이 기록될 수 있습니다.

근본 원인 - 버그```c

// Pseudocodice - WinRAR v7.11 (VULNERABILE) void extract_file(rar_entry *entry, char *dest_dir) { char final_path[MAX_PATH];

strcpy(final_path, dest_dir);         // "C:\\Temp\\"
strcat(final_path, entry->filename);  // + "..\\..\\..\\Windows\\System32\\malware.exe"

// ❌ ERRORE: Nessuna validazione del path traversal!
// final_path = "C:\\Temp\\..\\..\\..\\Windows\\System32\\malware.exe"
// Risolto come: "C:\\Windows\\System32\\malware.exe" ← EXPLOIT!

create_file(final_path);  // File creato in directory non intesa

}

### v7.11에서 누락된 보호 기능

- ❌ 파일이 `dest_dir` 내에 남아 있는지 확인하지 않음
- ❌ `..` 또는 `.` 시퀀스에 대한 필터 없음
- ❌ 경로 정규화 없음
- ❌ 허용된 디렉터리 화이트리스트 없음
- ❌ 컨테이너 유효성 검사 없음

### v7.12에서의 수정```c
// WinRAR v7.12 (PATCHED)
bool is_path_contained(char *path, char *base_dir) {
    char canonical[MAX_PATH], canonical_base[MAX_PATH];
    
    // Normalizza entrambi i percorsi
    GetFullPathName(path, MAX_PATH, canonical, NULL);
    GetFullPathName(base_dir, MAX_PATH, canonical_base, NULL);
    
    // Verifica contenimento
    if (strncmp(canonical, canonical_base, strlen(canonical_base)) != 0) {
        return false;  // Path esce dalla directory base
    }
    return true;
}

void extract_file_safe(rar_entry *entry, char *dest_dir) {
    char final_path[MAX_PATH];
    strcpy(final_path, dest_dir);
    strcat(final_path, entry->filename);
    
    // ✅ FIX: Verifica che il file rimane dentro dest_dir
    if (!is_path_contained(final_path, dest_dir)) {
        skip_extraction();  // Rifiuta estrazione
        log_error("Path traversal detected!");
        return;
    }
    
    create_file(final_path);  // Adesso sicuro
}

💥 익스플로잇 메커니즘

Path Traversal Explained```

Cartella di Estrazione: C:\Temp\Extract

Path nel RAR (craft): ..\..\..\..\Users\\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\payload.bat

Risoluzione Path: C:\Temp\Extract\.. = C:\Temp\ C:\Temp\.. = C:\ C:\.. = C:\ (non può andare oltre)

  • Users\\...\Startup\payload.bat

= C:\Users\\AppData\Roaming\...\Startup\payload.bat ✓

### 공격 흐름 다이어그램```
┌─────────────────────────────────────────────┐
│  1. Attaccante crea RAR con path craft     │
│     es: ..\\..\\..\\Startup\\malware.bat   │
└─────────────────────────────────────────────┘
                    ↓
┌─────────────────────────────────────────────┐
│  2. Distribuzione via spear-phishing        │
│     Email mirata con allegato RAR          │
└─────────────────────────────────────────────┘
                    ↓
┌─────────────────────────────────────────────┐
│  3. Vittima estrae archivio con WinRAR     │
│     (versione ≤ 7.11)                       │
└─────────────────────────────────────────────┘
                    ↓
┌─────────────────────────────────────────────┐
│  4. WinRAR non valida path traversal       │
│     File estratto in Startup folder         │
└─────────────────────────────────────────────┘
                    ↓
┌─────────────────────────────────────────────┐
│  5. Al boot: payload eseguito              │
│     RAT stabilisce C2 connection            │
└─────────────────────────────────────────────┘

🔴 취약한 버전

호환성 표

버전상태참고
≤ 7.10🔴 취약모든 익스플로잇이 작동함
7.11🔴 취약마지막 취약 버전
7.12 Beta 1+🟢 패치됨경로 탐색 수정
7.12+🟢 패치됨수정된 안정 릴리스
UNIX / Android✅ 영향 없음Windows 이외 버전은 영향을 받지 않음

버전 확인 방법```powershell

Metodo 1: PowerShell

(Get-Item "C:\Program Files\WinRAR\WinRAR.exe").VersionInfo.FileVersion

Output:

7.11.0.0 → 🔴 VULNERABILE ⚠️

7.12.0.0 → 🟢 SAFE ✓

Metodo 2: CMD

wmic datafile where name="C:\\Program Files\\WinRAR\\WinRAR.exe" get Version

Metodo 3: GUI

WinRAR → Help → About WinRAR → Verifica versione

---

## 🌍 공격 시나리오

### 시나리오 1: Bitter/APT-C-08 Spear-Phishing (활성 확인됨)

**목표**: 정부, 군사 조직, 전략 기관```
Email Phishing:
  From: [email protected]
  Subject: "Provision of Information for Sectoral for AJK.rar"
  Attachment: Provision_of_Information.rar

Contenuto Archive:
  ├── Document.docx (esca legittima - report convincente)
  └── ..\\..\\..\\..\\Users\\User\\AppData\\Roaming\\Microsoft\\Office\\STARTUP\\Template.dotm
      (macro malato nascosto)

Esecuzione:
  1. Vittima estrae RAR
  2. WinRAR non valida path → Template.dotm finisce in Office STARTUP
  3. Prossimo avvio Word → Macro eseguita automaticamente
  4. PowerShell downloader attivato
  5. C# Trojan scaricato: WmRAT, MiyaRAT, ZxxZ
  6. C2 Server: johnfashionaccess.com
  7. Capabilities:
     - Keylogging
     - Screenshot capture
     - RDP credential stealing
     - File exfiltration
     - Lateral movement

시나리오 2: GOFFEE Multi-Stage Payload

목표: 러시아 정부 기관``` RAR specializzato: ├── run.bat (path: ..\..\..\..\Windows\Startup\run.bat) └── legitimate_document.pdf (esca)

Attack Chain:

  1. Estrazione RAR → run.bat finisce in Startup
  2. Al prossimo boot → run.bat eseguito
  3. PowerShell script scarica stage 2
  4. C# Custom Trojan installato
  5. RAT stabilisce C2 persistente
  6. Full system control achieved
### 시나리오 3: Ransomware 전달```
RAR Weaponized:
  └── locker.exe (path: ..\\..\\..\\Startup\\locker.exe)

Infezione:
  1. Estrazione RAR
  2. locker.exe → Startup folder
  3. Sistema reboota (naturale o forzato)
  4. locker.exe eseguito con diritti user
  5. File system encryption
  6. Ransom note displayed
  7. Bitcoin payment richiesto

🎭 위협 행위자

GOFFEE (Paper Werewolf) 🇷🇺

  • 출처: 러시아
  • 최초 발견: 2025년 7월
  • 대상: 러시아 정부 기관
  • 방법: CVE-2025-6218 + CVE-2025-8088 (NTFS ADS)
  • 페이로드: C# Custom Trojan
  • TTP: 다단계 감염, NTFS ADS 악용

Bitter / APT-C-08 / Manlinghua 🇵🇰

  • 출처: 남아시아
  • 최초 발견: 2025년 8월
  • 대상: 정부, 군사, 전략 기관
  • 방법: RAR + 매크로 템플릿을 사용한 스피어 피싱
  • 페이로드: WmRAT, MiyaRAT, ZxxZ
  • C2: johnfashionaccess.com
  • TTP: 사회 공학, Office 매크로 악용
  • 상태: 🔴 활성 캠페인

Gamaredon 🇷🇺

  • 출처: 러시아 (FSB와 연계된 APT)
  • 최초 발견: 2025년 11월
  • 대상: 우크라이나 정부
  • 페이로드: GamaWiper (데이터 파괴)
  • 유형: 사이버 사보타지 및 스파이 활동
  • TTP: 대량 유포, 와이퍼 배포

🧪 개념 증명

도구 다운로드