¡¾¸´ÏÖ¡¿Windows PowerShellÏÂÁî×¢ÈëÎó²î£¨CVE-2025-54100£©

Ðû²¼Ê±¼ä 2025-12-26

Windows PowerShellÊÇ΢ÈíΪWindowsϵͳ¿ª·¢µÄʹÃü×Ô¶¯»¯ºÍÉèÖùÜÀí¿ò¼Ü£¬£¬£¬£¬ £¬°üÀ¨ÏÂÁîÐÐshellºÍ¾ç±¾ÓïÑÔ¡£¡£¡£¡£¡£²î±ðÓڹŰåShell´¦Öóͷ£Îı¾Á÷£¬£¬£¬£¬ £¬Ëü»ùÓÚ .NETÔËÐÐÇéÐΣ¬£¬£¬£¬ £¬Ö±½Ó²Ù×÷½á¹¹»¯¹¤¾ß¡£¡£¡£¡£¡£


2025Äê12ÔÂ΢ÈíÐû²¼Á˸üУ¬£¬£¬£¬ £¬Åû¶ÁËPowerShellÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2025-54100£©£¬£¬£¬£¬ £¬CVSSÆÀ·Ö7.8·Ö¡£¡£¡£¡£¡£


΢Èí¹Ù·½¶Ô¸ÃÎó²îµÄÐÎòÊÇ£º"Improper neutralization of special elements used in a command ('command injection') in Windows PowerShell allows an unauthorized attacker to execute code locally."


Ó°Ïì¹æÄ£


Windows 10 Version 1607 < 10.0.20348.4529 

Windows 10 Version 1809 < 10.0.17763.8146 

Windows 10 Version 21H2 < 10.0.19044.6691 

Windows 10 Version 22H2 < 10.0.19045.6691 

Windows 11 Version 23H2 < 10.0.25398.2025 

Windows 11 Version 24H2 < 10.0.26100.7462 

Windows 11 Version 25H2 < 10.0.26200.7462 

Windows Server 2008 SP2 < 6.0.6003.23666 

Windows Server 2008 R2 < 6.1.7601.28064 

Windows Server 2012 < 6.2.9200.25815 

Windows Server 2012 R2 < 6.3.9600.22920 

Windows Server 2016 < 10.0.14393.8688 

Windows Server 2019 < 10.0.17763.8146 

Windows Server 2022 < 10.0.20348.4529 

Windows Server 2022 23H2 < 10.0.25398.2025

Windows Server 2025 < 10.0.26100.7462


Îó²îÔ­Àí


ÔÚ΢ÈíÅû¶µÄÐÅÏ¢ÖÐÏÔʾ¸ÃÎó²îÓëInvoke-WebRequestÏÂÁîÓйء£¡£¡£¡£¡£Í¨¹ý΢ÈíµÄÊÖÒÕÎĵµÏàʶµ½£¬£¬£¬£¬ £¬Invoke-WebRequest cmdlet½«HTTPºÍHTTPSÇëÇó·¢Ë͵½ÍøÒ³»òWeb·þÎñ£¬£¬£¬£¬ £¬Ëü½«ÆÊÎöÏìÓ¦²¢ÆÊÎöÍøÒ³ÄÚÈÝ¡£¡£¡£¡£¡£


ͼƬ1.png


½øÒ»²½Ñо¿Î¢ÈíµÄÊÖÒÕÎĵµ·¢Ã÷£¬£¬£¬£¬ £¬ÔÚPowerShellµÄ5.1°æ±¾ÖУ¬£¬£¬£¬ £¬Invoke-WebRequestÏÂÁîĬÈÏʹÓÃInternet ExplorerµÄMSHTML£¨Trident£©ÒýÇæ¾ÙÐÐÍêÕûµÄHTMLÆÊÎöäÖȾ£¬£¬£¬£¬ £¬Õ⽫µ¼ÖÂÍøÒ³ÖеÄJavaScript¡¢iframe¡¢ActiveX¡¢VBScriptµÈÄÚÈÝ»á±»ÕæÊµ¼ÓÔØ²¢Ö´ÐС£¡£¡£¡£¡£


¾­ÓÉÒ»·¬ÊӲ죬£¬£¬£¬ £¬ÎÒÃÇ·¢Ã÷12Ô·ÝǰµÄWindows 11¡¢Server 22 ºÍ Server 25ĬÈϰ汾Öж¼¸½´øÁËPowerShell 5.1°æ±¾¡£¡£¡£¡£¡£


Îó²î¸´ÏÖ


ͼƬ2.png


Çå¾²½¨Òé


¡ã Windows×Ô¶¯¸üÐÂ


¸üÐÂÖÁϵͳ¶ÔÓ¦×îа汾¡£¡£¡£¡£¡£


¡ã ÊÖ¶¯×°Öò¹¶¡


¹ØÓÚÎÞ·¨×Ô¶¯¸üеÄϵͳ£¬£¬£¬£¬ £¬¿ÉÒÔͨ¹ýÏÂÃæµÄÁ´½ÓÏÂÔØ¶ÔӦϵͳµÄÇå¾²²¹¶¡£¡£¡£¡£¡£ºhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-54100¡£¡£¡£¡£¡£


ͼƬ3.png


²Î¿¼Á´½Ó£º

[1]https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-54100


³¬·²ÓéÀÖ¹ÙÍøÆð¾¢·ÀÓùʵÑéÊÒ£¨ADLab£©


ADLab½¨ÉèÓÚ1999Ä꣬£¬£¬£¬ £¬ÊÇÖйúÇå¾²ÐÐÒµ×îÔ罨ÉèµÄ¹¥·ÀÊÖÒÕÑо¿ÊµÑéÊÒÖ®Ò»£¬£¬£¬£¬ £¬Î¢ÈíMAPPÍýÏë½¹µã³ÉÔ±£¬£¬£¬£¬ £¬¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕß¡£¡£¡£¡£¡£×èÖ¹ÏÖÔÚ£¬£¬£¬£¬ £¬ADLabÒÑͨ¹ý CNVD/CNNVD/NVDB/CVEÀÛ¼ÆÐû²¼Çå¾²Îó²î6500Óà¸ö£¬£¬£¬£¬ £¬Ò»Á¬¼á³Ö¹ú¼ÊÍøÂçÇå¾²ÁìÓòÒ»Á÷Ë®×¼¡£¡£¡£¡£¡£ÊµÑéÊÒÑо¿Æ«Ïòº­¸Ç»ù´¡Çå¾²Ñо¿¡¢Êý¾ÝÇå¾²Ñо¿¡¢5GÇå¾²Ñо¿¡¢AI+Çå¾²Ñо¿¡¢ÎÀÐÇÇå¾²Ñо¿¡¢ÔËÓªÉÌ»ù´¡ÉèÊ©Çå¾²Ñо¿¡¢Òƶ¯Çå¾²Ñо¿¡¢ÎïÁªÍøÇå¾²Ñо¿¡¢³µÁªÍøÇå¾²Ñо¿¡¢¹¤¿ØÇå¾²Ñо¿¡¢ÐÅ´´Çå¾²Ñо¿¡¢ÔÆÇå¾²Ñо¿¡¢ÎÞÏßÇå¾²Ñо¿¡¢¸ß¼¶ÍþвÑо¿¡¢¹¥·À¶Ô¿¹ÊÖÒÕÑо¿¡£¡£¡£¡£¡£Ñо¿Ð§¹ûÓ¦ÓÃÓÚ²úÆ·½¹µãÊÖÒÕÑо¿¡¢¹ú¼ÒÖØµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÇå¾²·þÎñµÈ¡£¡£¡£¡£¡£


adlab.jpg