¡¾¸´ÏÖ¡¿Windows PowerShellºÅÁî×¢Èë·ì϶£¨CVE-2025-54100£©
°ä²¼¹¦·ò 2025-12-26Windows PowerShellÊÇ΢ÈíΪWindowsϵͳ¿ª·¢µÄ¹¤×÷×Ô¶¯»¯ºÍÅäÖÃÖÎÀí¿ò¼Ü£¬£¬Ô̺¬ºÅÁîÐÐshellºÍ¾ç±¾Ëµ»°¡£¡£¡£¡£·ÖÆçÓÚ´«Í³Shell´¦ÖÃÎı¾Á÷£¬£¬Ëü»ùÓÚ .NETÔËÐл·¾³£¬£¬Ö±½Ó²Ù×÷½á¹¹»¯¶ÔÏ󡣡£¡£¡£
2025Äê12ÔÂ΢Èí°ä²¼Á˸üУ¬£¬Åû¶ÁËPowerShellÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2025-54100£©£¬£¬CVSSÆÀ·Ö7.8·Ö¡£¡£¡£¡£
΢Èí¹Ù·½¶Ô¸Ã·ì϶µÄÃèÊöÊÇ£º£º"Improper neutralization of special elements used in a command ('command injection') in Windows PowerShell allows an unauthorized attacker to execute code locally."
Ó°ÏìÁìÓò
Windows 10 Version 1607 < 10.0.20348.4529
Windows 10 Version 1809 < 10.0.17763.8146
Windows 10 Version 21H2 < 10.0.19044.6691
Windows 10 Version 22H2 < 10.0.19045.6691
Windows 11 Version 23H2 < 10.0.25398.2025
Windows 11 Version 24H2 < 10.0.26100.7462
Windows 11 Version 25H2 < 10.0.26200.7462
Windows Server 2008 SP2 < 6.0.6003.23666
Windows Server 2008 R2 < 6.1.7601.28064
Windows Server 2012 < 6.2.9200.25815
Windows Server 2012 R2 < 6.3.9600.22920
Windows Server 2016 < 10.0.14393.8688
Windows Server 2019 < 10.0.17763.8146
Windows Server 2022 < 10.0.20348.4529
Windows Server 2022 23H2 < 10.0.25398.2025
Windows Server 2025 < 10.0.26100.7462
·ì϶µÀÀí
ÔÚ΢ÈíÅû¶µÄÐÅÏ¢ÖÐÏÔʾ¸Ã·ì϶ÓëInvoke-WebRequestºÅÁîÓйء£¡£¡£¡£Í¨¹ý΢ÈíµÄ¼¼ÊõÎĵµÏàʶµ½£¬£¬Invoke-WebRequest cmdlet½«HTTPºÍHTTPSÒªÇó·¢Ë͵½ÍøÒ³»òWeb·þÎñ£¬£¬Ëü½«·ÖÎöÏìÓ¦²¢½âÎöÍøÒ³ÄÚÈÝ¡£¡£¡£¡£

½øÒ»²½×êÑÐ΢ÈíµÄ¼¼ÊõÎĵµ·¢ÏÖ£¬£¬ÔÚPowerShellµÄ5.1°æ±¾ÖУ¬£¬Invoke-WebRequestºÅÁîĬÈÏʹÓÃInternet ExplorerµÄMSHTML£¨Trident£©ÒýÇæ½øÐÐÆëÈ«µÄHTML½âÎöäÖȾ£¬£¬Õ⽫µ¼ÖÂÍøÒ³ÖеÄJavaScript¡¢¡¢¡¢iframe¡¢¡¢¡¢ActiveX¡¢¡¢¡¢VBScriptµÈÄÚÈÝ»á±»ÕæÊµ¼ÓÔØ²¢Ö´ÐС£¡£¡£¡£
¾¹ýÒ»·¬µ÷²é£¬£¬ÎÒÃÇ·¢ÏÖ12Ô·ÝǰµÄWindows 11¡¢¡¢¡¢Server 22 ºÍ Server 25ĬÈϰ汾Öж¼¸½´øÁËPowerShell 5.1°æ±¾¡£¡£¡£¡£
·ì϶¸´ÏÖ

°²È«½¨Òé
¡ã Windows×Ô¶¯¸üÐÂ
¸üÐÂÖÁϵͳ¶ÔÓ¦×îа汾¡£¡£¡£¡£
¡ã ÊÖ¶¯×°Öò¹¶¡
¶ÔÓÚÎÞ·¨×Ô¶¯¸üеÄϵͳ£¬£¬Äܹ»Í¨¹ýÏÂÃæµÄÁ´½ÓÏÂÔØ¶ÔӦϵͳµÄ°²È«²¹¶¡£¡£¡£¡£º£ºhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-54100¡£¡£¡£¡£

[1]https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-54100
OG¶«·½Ìü»ý¼«·ÀÓù³¢ÊÔÊÒ£¨ADLab£©
ADLab³ÉÁ¢ÓÚ1999Ä꣬£¬ÊÇÖйú°²È«ÐÐÒµ×îÔç³ÉÁ¢µÄ¹¥·À¼¼Êõ×êÑг¢ÊÔÊÒÖ®Ò»£¬£¬Î¢ÈíMAPP´òËãÖ÷Ìâ³ÉÔ±£¬£¬¡°ºÚȸ¹¥»÷¡±¸ÅÄîÊ×ÍÆÕß¡£¡£¡£¡£½ØÖÁĿǰ£¬£¬ADLabÒÑͨ¹ý CNVD/CNNVD/NVDB/CVEÀۼư䲼°²È«·ì϶6500Óà¸ö£¬£¬³ÖÐøÎ¬³Ö¹ú¼ÊÍøÂ簲ȫÁìÓòÒ»Á÷Ë®×¼¡£¡£¡£¡£³¢ÊÔÊÒ×êÑз½Ïòº¸Ç»ù´¡°²È«×êÑС¢¡¢¡¢Êý¾Ý°²È«×êÑС¢¡¢¡¢5G°²È«×êÑС¢¡¢¡¢AI+°²È«×êÑС¢¡¢¡¢ÎÀÐǰ²È«×êÑС¢¡¢¡¢ÔËÓªÉÌ»ù´¡ÉèÊ©°²È«×êÑС¢¡¢¡¢Òƶ¯°²È«×êÑС¢¡¢¡¢ÎïÁªÍø°²È«×êÑС¢¡¢¡¢³µÁªÍø°²È«×êÑС¢¡¢¡¢¹¤¿Ø°²È«×êÑС¢¡¢¡¢ÐÅ´´°²È«×êÑС¢¡¢¡¢Ôư²È«×êÑС¢¡¢¡¢ÎÞÏß°²È«×êÑС¢¡¢¡¢¸ß¼¶Íþв×êÑС¢¡¢¡¢¹¥·ÀÆ¥µÐ¼¼Êõ×êÑС£¡£¡£¡£×êÑгɾÍÀûÓÃÓÚ²úÆ·Ö÷Ìâ¼¼Êõ×êÑС¢¡¢¡¢¹ú¶ÈÖØµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢¡¢¡¢×¨Òµ°²È«·þÎñµÈ¡£¡£¡£¡£



¾©¹«Íø°²±¸11010802024551ºÅ