¡¾¸´ÏÖ¡¿Windows PowerShellºÅÁî×¢Èë·ì϶£¨CVE-2025-54100£©

°ä²¼¹¦·ò 2025-12-26

Windows PowerShellÊÇ΢ÈíΪWindowsϵͳ¿ª·¢µÄ¹¤×÷×Ô¶¯»¯ºÍÅäÖÃÖÎÀí¿ò¼Ü£¬£¬ £¬£¬£¬£¬£¬£¬Ô̺¬ºÅÁîÐÐshellºÍ¾ç±¾Ëµ»°¡£¡£¡£¡£¡£¡£¡£·ÖÆçÓÚ´«Í³Shell´¦ÖÃÎı¾Á÷£¬£¬ £¬£¬£¬£¬£¬£¬Ëü»ùÓÚ .NETÔËÐл·¾³£¬£¬ £¬£¬£¬£¬£¬£¬Ö±½Ó²Ù×÷½á¹¹»¯¶ÔÏ󡣡£¡£¡£¡£¡£¡£


2025Äê12ÔÂ΢Èí°ä²¼Á˸üУ¬£¬ £¬£¬£¬£¬£¬£¬Åû¶ÁËPowerShellÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2025-54100£©£¬£¬ £¬£¬£¬£¬£¬£¬CVSSÆÀ·Ö7.8·Ö¡£¡£¡£¡£¡£¡£¡£


΢Èí¹Ù·½¶Ô¸Ã·ì϶µÄÃèÊöÊÇ£º"Improper neutralization of special elements used in a command ('command injection') in Windows PowerShell allows an unauthorized attacker to execute code locally."


Ó°ÏìÁìÓò


Windows 10 Version 1607 < 10.0.20348.4529 

Windows 10 Version 1809 < 10.0.17763.8146 

Windows 10 Version 21H2 < 10.0.19044.6691 

Windows 10 Version 22H2 < 10.0.19045.6691 

Windows 11 Version 23H2 < 10.0.25398.2025 

Windows 11 Version 24H2 < 10.0.26100.7462 

Windows 11 Version 25H2 < 10.0.26200.7462 

Windows Server 2008 SP2 < 6.0.6003.23666 

Windows Server 2008 R2 < 6.1.7601.28064 

Windows Server 2012 < 6.2.9200.25815 

Windows Server 2012 R2 < 6.3.9600.22920 

Windows Server 2016 < 10.0.14393.8688 

Windows Server 2019 < 10.0.17763.8146 

Windows Server 2022 < 10.0.20348.4529 

Windows Server 2022 23H2 < 10.0.25398.2025

Windows Server 2025 < 10.0.26100.7462


·ì϶µÀÀí


ÔÚ΢ÈíÅû¶µÄÐÅÏ¢ÖÐÏÔʾ¸Ã·ì϶ÓëInvoke-WebRequestºÅÁîÓйء£¡£¡£¡£¡£¡£¡£Í¨¹ý΢ÈíµÄ¼¼ÊõÎĵµÏàʶµ½£¬£¬ £¬£¬£¬£¬£¬£¬Invoke-WebRequest cmdlet½«HTTPºÍHTTPSÒªÇó·¢Ë͵½ÍøÒ³»òWeb·þÎñ£¬£¬ £¬£¬£¬£¬£¬£¬Ëü½«·ÖÎöÏìÓ¦²¢½âÎöÍøÒ³ÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£


ͼƬ1.png


½øÒ»²½×êÑÐ΢ÈíµÄ¼¼ÊõÎĵµ·¢ÏÖ£¬£¬ £¬£¬£¬£¬£¬£¬ÔÚPowerShellµÄ5.1°æ±¾ÖУ¬£¬ £¬£¬£¬£¬£¬£¬Invoke-WebRequestºÅÁîĬÈÏʹÓÃInternet ExplorerµÄMSHTML£¨Trident£©ÒýÇæ½øÐÐÆëÈ«µÄHTML½âÎöäÖȾ£¬£¬ £¬£¬£¬£¬£¬£¬Õ⽫µ¼ÖÂÍøÒ³ÖеÄJavaScript¡¢iframe¡¢ActiveX¡¢VBScriptµÈÄÚÈÝ»á±»ÕæÊµ¼ÓÔØ²¢Ö´ÐÓ×£¡£¡£¡£¡£¡£¡£


¾­¹ýÒ»·¬µ÷²é£¬£¬ £¬£¬£¬£¬£¬£¬ÎÒÃÇ·¢ÏÖ12Ô·ÝǰµÄWindows 11¡¢Server 22 ºÍ Server 25ĬÈϰ汾Öж¼¸½´øÁËPowerShell 5.1°æ±¾¡£¡£¡£¡£¡£¡£¡£


·ì϶¸´ÏÖ


ͼƬ2.png


°²È«½¨Òé


¡ã Windows×Ô¶¯¸üÐÂ


¸üÐÂÖÁϵͳ¶ÔÓ¦×îа汾¡£¡£¡£¡£¡£¡£¡£


¡ã ÊÖ¶¯×°Öò¹¶¡


¶ÔÓÚÎÞ·¨×Ô¶¯¸üеÄϵͳ£¬£¬ £¬£¬£¬£¬£¬£¬Äܹ»Í¨¹ýÏÂÃæµÄÁ´½ÓÏÂÔØ¶ÔӦϵͳµÄ°²È«²¹¶¡£¡£¡£¡£¡£¡£¡£ºhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-54100¡£¡£¡£¡£¡£¡£¡£


ͼƬ3.png


²Î¿¼Á´½Ó£º

[1]https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-54100


8827Ì«Ñô¼¯ÍÅ»ý¼«·ÀÓù³¢ÊÔÊÒ£¨ADLab£©


ADLab³ÉÁ¢ÓÚ1999Ä꣬£¬ £¬£¬£¬£¬£¬£¬ÊÇÖйú°²È«ÐÐÒµ×îÔç³ÉÁ¢µÄ¹¥·À¼¼Êõ×êÑг¢ÊÔÊÒÖ®Ò»£¬£¬ £¬£¬£¬£¬£¬£¬Î¢ÈíMAPP´òËãÖ÷Ìâ³ÉÔ±£¬£¬ £¬£¬£¬£¬£¬£¬¡°ºÚȸ¹¥»÷¡±¸ÅÏëÊ×ÍÆÕß¡£¡£¡£¡£¡£¡£¡£½ØÖÁĿǰ£¬£¬ £¬£¬£¬£¬£¬£¬ADLabÒÑͨ¹ý CNVD/CNNVD/NVDB/CVEÀۼư䲼°²È«·ì϶6500Óà¸ö£¬£¬ £¬£¬£¬£¬£¬£¬³ÖÐøÎ¬³Ö¹ú¼ÊÍøÂ簲ȫÁìÓòÒ»Á÷Ë®×¼¡£¡£¡£¡£¡£¡£¡£³¢ÊÔÊÒ×êÑз½Ïòº­¸Ç»ù´¡°²È«×êÑÓ×¢Êý¾Ý°²È«×êÑÓ×¢5G°²È«×êÑÓ×¢AI+°²È«×êÑÓ×¢ÎÀÐǰ²È«×êÑÓ×¢ÔËÓªÉÌ»ù´¡ÉèÊ©°²È«×êÑÓ×¢ÒÆ¶¯°²È«×êÑÓ×¢ÎïÁªÍø°²È«×êÑÓ×¢³µÁªÍø°²È«×êÑÓ×¢¹¤¿Ø°²È«×êÑÓ×¢ÐÅ´´°²È«×êÑÓ×¢ÔÆ°²È«×êÑÓ×¢ÎÞÏß°²È«×êÑÓ×¢¸ß¼¶Íþв×êÑÓ×¢¹¥·ÀÆ¥µÐ¼¼Êõ×êÑÓ×£¡£¡£¡£¡£¡£¡£×êÑгɾÍÀûÓÃÓÚ²úÆ·Ö÷Ìâ¼¼Êõ×êÑÓ×¢¹ú¶È³Áµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨Òµ°²È«·þÎñµÈ¡£¡£¡£¡£¡£¡£¡£


adlab.jpg