Skip to content
KitploitKITPLOIT
工具博客
Log in
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2025-6218-WinRAR-RCE-POC — 针对CVE-2025-6218的全面分析与概念验证——影响7.11及更早版本的WinRAR路径遍历远程代码执行漏洞 | Kitploit
工具/GitHubGitHub/chrxstxqn/cve-2025-6218-winrar-rce-poc
钓鱼工具持久化机制漏洞分析漏洞利用横向移动恶意软件分析渗透测试学习与教育二进制利用

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
GitHubchrxstxqn/cve-2025-6218-winrar-rce-poc

CVE-2025-6218-WinRAR-RCE-POC

针对CVE-2025-6218的全面分析与概念验证——影响7.11及更早版本的WinRAR路径遍历远程代码执行漏洞

查看仓库
21199个月前尚未审核

CVE-2025-6218: WinRAR 路径遍历远程代码执行漏洞

CVE CVSS Score Platform License Status

⚠️ 严重漏洞 - 已确认活跃利用

CVE-2025-6218 是 WinRAR 中的一个严重路径遍历漏洞,可导致任意代码执行。当前已被 APT 组织如 GOFFEE、Bitter (APT-C-08) 和 Gamaredon 利用。


📋 目录

  • 概述
  • 技术描述
  • 利用机制
  • 受影响版本
  • 攻击场景
  • 威胁行为体
  • 概念验证
  • 检测与入侵指标
  • 缓解措施
  • 时间线
  • 仓库结构
  • 参考

🎯 概述

CVE-2025-6218 是 WinRAR for Windows 中的一个严重的路径遍历漏洞,攻击者可借此执行任意代码。

主要影响

方面详情
CVSS 评分7.8(高危)
受影响版本WinRAR ≤ 7.11(仅 Windows)
平台Windows 10、11、Server
受影响用户约 5 亿
修复版本WinRAR 7.12(2025 年 6 月)
状态🔴 正在被活跃利用
CISA KEV2025 年 12 月 9 日添加

为何危险?

攻击者可:

  • ✅ 将文件放入敏感目录(启动项、System32)
  • ✅ 在系统启动时执行代码
  • ✅ 无需高权限即可建立持久化
  • ✅ 绕过杀毒软件(利用合法工具)
  • ✅ 在企业网络中进行横向移动

🔍 技术描述

漏洞是什么?

WinRAR 未正确验证特制 .rar 存档中文件的路径。当用户解压恶意构造的存档时,文件可通过路径遍历序列(../ 或 ..\\)被写入到预期解压目录之外的任意路径。

根本原因 - 漏洞```c

// Pseudocodice - WinRAR v7.11 (VULNERABILE) void extract_file(rar_entry *entry, char *dest_dir) { char final_path[MAX_PATH];

strcpy(final_path, dest_dir);         // "C:\\Temp\\"
strcat(final_path, entry->filename);  // + "..\\..\\..\\Windows\\System32\\malware.exe"

// ❌ ERRORE: Nessuna validazione del path traversal!
// final_path = "C:\\Temp\\..\\..\\..\\Windows\\System32\\malware.exe"
// Risolto come: "C:\\Windows\\System32\\malware.exe" ← EXPLOIT!

create_file(final_path);  // File creato in directory non intesa

}

### v7.11 中缺失的保护

- ❌ 未检查文件是否保留在 `dest_dir` 内
- ❌ 未过滤 `..` 或 `.` 序列
- ❌ 未对路径进行规范化
- ❌ 未设置允许的目录白名单
- ❌ 未进行路径包含验证

### v7.12 中的修复

- ✅ 通过 `os.path.realpath(dest_dir)` 进行包含性检查```c
// WinRAR v7.12 (PATCHED)
bool is_path_contained(char *path, char *base_dir) {
    char canonical[MAX_PATH], canonical_base[MAX_PATH];
    
    // Normalizza entrambi i percorsi
    GetFullPathName(path, MAX_PATH, canonical, NULL);
    GetFullPathName(base_dir, MAX_PATH, canonical_base, NULL);
    
    // Verifica contenimento
    if (strncmp(canonical, canonical_base, strlen(canonical_base)) != 0) {
        return false;  // Path esce dalla directory base
    }
    return true;
}

void extract_file_safe(rar_entry *entry, char *dest_dir) {
    char final_path[MAX_PATH];
    strcpy(final_path, dest_dir);
    strcat(final_path, entry->filename);
    
    // ✅ FIX: Verifica che il file rimane dentro dest_dir
    if (!is_path_contained(final_path, dest_dir)) {
        skip_extraction();  // Rifiuta estrazione
        log_error("Path traversal detected!");
        return;
    }
    
    create_file(final_path);  // Adesso sicuro
}

💥 漏洞利用机制

路径遍历详解```

Cartella di Estrazione: C:\Temp\Extract

Path nel RAR (craft): ..\..\..\..\Users\\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\payload.bat

Risoluzione Path: C:\Temp\Extract\.. = C:\Temp\ C:\Temp\.. = C:\ C:\.. = C:\ (non può andare oltre)

  • Users\\...\Startup\payload.bat

= C:\Users\\AppData\Roaming\...\Startup\payload.bat ✓

### 攻击流程图```
┌─────────────────────────────────────────────┐
│  1. Attaccante crea RAR con path craft     │
│     es: ..\\..\\..\\Startup\\malware.bat   │
└─────────────────────────────────────────────┘
                    ↓
┌─────────────────────────────────────────────┐
│  2. Distribuzione via spear-phishing        │
│     Email mirata con allegato RAR          │
└─────────────────────────────────────────────┘
                    ↓
┌─────────────────────────────────────────────┐
│  3. Vittima estrae archivio con WinRAR     │
│     (versione ≤ 7.11)                       │
└─────────────────────────────────────────────┘
                    ↓
┌─────────────────────────────────────────────┐
│  4. WinRAR non valida path traversal       │
│     File estratto in Startup folder         │
└─────────────────────────────────────────────┘
                    ↓
┌─────────────────────────────────────────────┐
│  5. Al boot: payload eseguito              │
│     RAT stabilisce C2 connection            │
└─────────────────────────────────────────────┘

🔴 受影响版本

兼容性表

版本状态备注
≤ 7.10🔴 有漏洞所有漏洞利用均有效
7.11🔴 有漏洞最后一个受影响版本
7.12 Beta 1+🟢 已修复路径遍历修复
7.12+🟢 已修复包含修复的稳定版本
UNIX / Android✅ 不受影响非 Windows 版本不受影响

如何检查你的版本```powershell

Metodo 1: PowerShell

(Get-Item "C:\Program Files\WinRAR\WinRAR.exe").VersionInfo.FileVersion

Output:

7.11.0.0 → 🔴 VULNERABILE ⚠️

7.12.0.0 → 🟢 SAFE ✓

Metodo 2: CMD

wmic datafile where name="C:\\Program Files\\WinRAR\\WinRAR.exe" get Version

Metodo 3: GUI

WinRAR → Help → About WinRAR → Verifica versione

---

## 🌍 攻击场景

### 场景1: Bitter/APT-C-08 鱼叉式钓鱼(确认活跃)

**目标**: 政府、军事组织、战略机构```
Email Phishing:
  From: [email protected]
  Subject: "Provision of Information for Sectoral for AJK.rar"
  Attachment: Provision_of_Information.rar

Contenuto Archive:
  ├── Document.docx (esca legittima - report convincente)
  └── ..\\..\\..\\..\\Users\\User\\AppData\\Roaming\\Microsoft\\Office\\STARTUP\\Template.dotm
      (macro malato nascosto)

Esecuzione:
  1. Vittima estrae RAR
  2. WinRAR non valida path → Template.dotm finisce in Office STARTUP
  3. Prossimo avvio Word → Macro eseguita automaticamente
  4. PowerShell downloader attivato
  5. C# Trojan scaricato: WmRAT, MiyaRAT, ZxxZ
  6. C2 Server: johnfashionaccess.com
  7. Capabilities:
     - Keylogging
     - Screenshot capture
     - RDP credential stealing
     - File exfiltration
     - Lateral movement

场景 2:GOFFEE 多阶段载荷

目标:俄罗斯政府组织``` RAR specializzato: ├── run.bat (path: ..\..\..\..\Windows\Startup\run.bat) └── legitimate_document.pdf (esca)

Attack Chain:

  1. Estrazione RAR → run.bat finisce in Startup
  2. Al prossimo boot → run.bat eseguito
  3. PowerShell script scarica stage 2
  4. C# Custom Trojan installato
  5. RAT stabilisce C2 persistente
  6. Full system control achieved
### 场景3:勒索软件投递```
RAR Weaponized:
  └── locker.exe (path: ..\\..\\..\\Startup\\locker.exe)

Infezione:
  1. Estrazione RAR
  2. locker.exe → Startup folder
  3. Sistema reboota (naturale o forzato)
  4. locker.exe eseguito con diritti user
  5. File system encryption
  6. Ransom note displayed
  7. Bitcoin payment richiesto

🎭 威胁行为者

GOFFEE (纸狼) 🇷🇺

  • 来源: 俄罗斯
  • 首次发现: 2025年7月
  • 目标: 俄罗斯政府机构
  • 方法: CVE-2025-6218 + CVE-2025-8088 (NTFS ADS)
  • 有效载荷: C# 自定义木马
  • TTP: 多阶段感染,NTFS ADS 滥用

Bitter / APT-C-08 / Manlinghua 🇵🇰

  • 来源: 南亚
  • 首次发现: 2025年8月
  • 目标: 政府、军事、战略组织
  • 方法: 鱼叉式钓鱼 (RAR + 宏模板)
  • 有效载荷: WmRAT, MiyaRAT, ZxxZ
  • C2: johnfashionaccess.com
  • TTP: 社会工程学,Office宏滥用
  • 状态: 🔴 活动中的攻击活动

Gamaredon 🇷🇺

  • 来源: 俄罗斯 (与FSB结盟的APT)
  • 首次发现: 2025年11月
  • 目标: 乌克兰政府
  • 有效载荷: GamaWiper (数据销毁)
  • 类型: 网络破坏 + 间谍活动
  • TTP: 大规模分发,擦除器部署

🧪 概念验证

先决条件```

✅ Windows VM (10, 11, Server) ✅ WinRAR versione ≤ 7.11 installato ✅ Network isolato (no internet - safety first!) ✅ Snapshot VM per rollback ✅ Admin access per testing

### 实验室环境设置```powershell
# 1. Crea VM Windows pulita
# 2. Installa WinRAR 7.11
winget install RARLab.WinRAR --version 7.11
下载工具