针对CVE-2025-6218的全面分析与概念验证——影响7.11及更早版本的WinRAR路径遍历远程代码执行漏洞
⚠️ 严重漏洞 - 已确认活跃利用
CVE-2025-6218 是 WinRAR 中的一个严重路径遍历漏洞,可导致任意代码执行。当前已被 APT 组织如 GOFFEE、Bitter (APT-C-08) 和 Gamaredon 利用。
CVE-2025-6218 是 WinRAR for Windows 中的一个严重的路径遍历漏洞,攻击者可借此执行任意代码。
| 方面 | 详情 |
|---|---|
| CVSS 评分 | 7.8(高危) |
| 受影响版本 | WinRAR ≤ 7.11(仅 Windows) |
| 平台 | Windows 10、11、Server |
| 受影响用户 | 约 5 亿 |
| 修复版本 | WinRAR 7.12(2025 年 6 月) |
| 状态 | 🔴 正在被活跃利用 |
| CISA KEV | 2025 年 12 月 9 日添加 |
攻击者可:
WinRAR 未正确验证特制 .rar 存档中文件的路径。当用户解压恶意构造的存档时,文件可通过路径遍历序列(../ 或 ..\\)被写入到预期解压目录之外的任意路径。
// Pseudocodice - WinRAR v7.11 (VULNERABILE) void extract_file(rar_entry *entry, char *dest_dir) { char final_path[MAX_PATH];
strcpy(final_path, dest_dir); // "C:\\Temp\\"
strcat(final_path, entry->filename); // + "..\\..\\..\\Windows\\System32\\malware.exe"
// ❌ ERRORE: Nessuna validazione del path traversal!
// final_path = "C:\\Temp\\..\\..\\..\\Windows\\System32\\malware.exe"
// Risolto come: "C:\\Windows\\System32\\malware.exe" ← EXPLOIT!
create_file(final_path); // File creato in directory non intesa
}
### v7.11 中缺失的保护
- ❌ 未检查文件是否保留在 `dest_dir` 内
- ❌ 未过滤 `..` 或 `.` 序列
- ❌ 未对路径进行规范化
- ❌ 未设置允许的目录白名单
- ❌ 未进行路径包含验证
### v7.12 中的修复
- ✅ 通过 `os.path.realpath(dest_dir)` 进行包含性检查```c
// WinRAR v7.12 (PATCHED)
bool is_path_contained(char *path, char *base_dir) {
char canonical[MAX_PATH], canonical_base[MAX_PATH];
// Normalizza entrambi i percorsi
GetFullPathName(path, MAX_PATH, canonical, NULL);
GetFullPathName(base_dir, MAX_PATH, canonical_base, NULL);
// Verifica contenimento
if (strncmp(canonical, canonical_base, strlen(canonical_base)) != 0) {
return false; // Path esce dalla directory base
}
return true;
}
void extract_file_safe(rar_entry *entry, char *dest_dir) {
char final_path[MAX_PATH];
strcpy(final_path, dest_dir);
strcat(final_path, entry->filename);
// ✅ FIX: Verifica che il file rimane dentro dest_dir
if (!is_path_contained(final_path, dest_dir)) {
skip_extraction(); // Rifiuta estrazione
log_error("Path traversal detected!");
return;
}
create_file(final_path); // Adesso sicuro
}
Cartella di Estrazione: C:\Temp\Extract
Path nel RAR (craft): ..\..\..\..\Users\\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\payload.bat
Risoluzione Path: C:\Temp\Extract\.. = C:\Temp\ C:\Temp\.. = C:\ C:\.. = C:\ (non può andare oltre)
= C:\Users\\AppData\Roaming\...\Startup\payload.bat ✓
### 攻击流程图```
┌─────────────────────────────────────────────┐
│ 1. Attaccante crea RAR con path craft │
│ es: ..\\..\\..\\Startup\\malware.bat │
└─────────────────────────────────────────────┘
↓
┌─────────────────────────────────────────────┐
│ 2. Distribuzione via spear-phishing │
│ Email mirata con allegato RAR │
└─────────────────────────────────────────────┘
↓
┌─────────────────────────────────────────────┐
│ 3. Vittima estrae archivio con WinRAR │
│ (versione ≤ 7.11) │
└─────────────────────────────────────────────┘
↓
┌─────────────────────────────────────────────┐
│ 4. WinRAR non valida path traversal │
│ File estratto in Startup folder │
└─────────────────────────────────────────────┘
↓
┌─────────────────────────────────────────────┐
│ 5. Al boot: payload eseguito │
│ RAT stabilisce C2 connection │
└─────────────────────────────────────────────┘
| 版本 | 状态 | 备注 |
|---|---|---|
| ≤ 7.10 | 🔴 有漏洞 | 所有漏洞利用均有效 |
| 7.11 | 🔴 有漏洞 | 最后一个受影响版本 |
| 7.12 Beta 1+ | 🟢 已修复 | 路径遍历修复 |
| 7.12+ | 🟢 已修复 | 包含修复的稳定版本 |
| UNIX / Android | ✅ 不受影响 | 非 Windows 版本不受影响 |
(Get-Item "C:\Program Files\WinRAR\WinRAR.exe").VersionInfo.FileVersion
wmic datafile where name="C:\\Program Files\\WinRAR\\WinRAR.exe" get Version
---
## 🌍 攻击场景
### 场景1: Bitter/APT-C-08 鱼叉式钓鱼(确认活跃)
**目标**: 政府、军事组织、战略机构```
Email Phishing:
From: [email protected]
Subject: "Provision of Information for Sectoral for AJK.rar"
Attachment: Provision_of_Information.rar
Contenuto Archive:
├── Document.docx (esca legittima - report convincente)
└── ..\\..\\..\\..\\Users\\User\\AppData\\Roaming\\Microsoft\\Office\\STARTUP\\Template.dotm
(macro malato nascosto)
Esecuzione:
1. Vittima estrae RAR
2. WinRAR non valida path → Template.dotm finisce in Office STARTUP
3. Prossimo avvio Word → Macro eseguita automaticamente
4. PowerShell downloader attivato
5. C# Trojan scaricato: WmRAT, MiyaRAT, ZxxZ
6. C2 Server: johnfashionaccess.com
7. Capabilities:
- Keylogging
- Screenshot capture
- RDP credential stealing
- File exfiltration
- Lateral movement
目标:俄罗斯政府组织``` RAR specializzato: ├── run.bat (path: ..\..\..\..\Windows\Startup\run.bat) └── legitimate_document.pdf (esca)
Attack Chain:
### 场景3:勒索软件投递```
RAR Weaponized:
└── locker.exe (path: ..\\..\\..\\Startup\\locker.exe)
Infezione:
1. Estrazione RAR
2. locker.exe → Startup folder
3. Sistema reboota (naturale o forzato)
4. locker.exe eseguito con diritti user
5. File system encryption
6. Ransom note displayed
7. Bitcoin payment richiesto
✅ Windows VM (10, 11, Server) ✅ WinRAR versione ≤ 7.11 installato ✅ Network isolato (no internet - safety first!) ✅ Snapshot VM per rollback ✅ Admin access per testing
### 实验室环境设置```powershell
# 1. Crea VM Windows pulita
# 2. Installa WinRAR 7.11
winget install RARLab.WinRAR --version 7.11