¡¾Îó²îͨ¸æ¡¿Notepad++ v8.8.1×°ÖóÌÐòÌØÈ¨ÌáÉýÎó²î (CVE-2025-49144)

Ðû²¼Ê±¼ä 2025-06-24

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

Notepad++ v8.8.×°ÖóÌÐòÌØÈ¨ÌáÉýÎó²î

CVE   ID

CVE-2025-49144

Îó²îÀàÐÍ

ÌØÈ¨ÌáÉýÎó²î

·¢Ã÷ʱ¼ä

2025-06-24

Îó²îÆÀ·Ö

7.3

Îó²îÆ·¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍâµØ

ËùÐèȨÏÞ

µÍ

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

ÐèÒª

PoC/EXP

ÒѹûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


Notepad++ÊÇÒ»¿îÃâ·ÑµÄ¿ªÔ´Îı¾±à¼­Æ÷ £¬£¬£¬£¬Ö§³Ö¶àÖÖ±à³ÌÓïÑÔµÄÓï·¨¸ßÁÁºÍ×Ô¶¯Íê³É¡£¡£Ëü»ùÓÚScintilla±à¼­¿Ø¼þ £¬£¬£¬£¬ÌṩǿʢµÄ¹¦Ð§ £¬£¬£¬£¬Èç¶à±êǩҳ±à¼­¡¢ÕýÔò±í´ïʽËÑË÷Ìæ»»¡¢²å¼þÀ©Õ¹ºÍ×Ô½ç˵¿ì½Ý¼üµÈ¡£¡£Notepad++ÊÊÓÃÓÚWindowsϵͳ £¬£¬£¬£¬ÆÕ±éÓÃÓÚ±à³Ì¡¢¾ç±¾±à¼­ÒÔ¼°Ò»Ñùƽ³£Îı¾´¦Öóͷ£¡£¡£ÒÀ¸½ÆäÇáÁ¿¼¶ºÍ¸ßЧÐÔ £¬£¬£¬£¬³ÉΪ¿ª·¢ÕߺÍÊÖÒÕÖ°Ô±µÄ³£Óù¤¾ß¡£¡£


2025Äê6ÔÂ24ÈÕ £¬£¬£¬£¬ÄϹ¬NGÓéÀÖ¼¯ÍÅVSRC¼à²âµ½notepad-plus-plusÐû²¼Ç徲ͨ¸æ £¬£¬£¬£¬Åû¶ÁËÒ»¸öÌØÈ¨ÌáÉýÎó²î¡£¡£¹¥»÷Õß¿ÉʹÓò»ÊÜ¿ØÖƵĿÉÖ´ÐÐÎļþËÑË÷·¾¶£¨EXE/DLLËÑË÷·¾¶£©ÔÚ×°ÖÃÀú³ÌÖÐ £¬£¬£¬£¬½«¶ñÒâ¿ÉÖ´ÐÐÎļþ¼ÓÔØÎªSYSTEMȨÏÞ £¬£¬£¬£¬´Ó¶øÊµÏÖÍâµØÌØÈ¨ÌáÉý¡£¡£Îó²îµÄPOCÒѹûÕæ £¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýÌØ¶¨µÄÎļþ·¾¶²Ù×÷´¥·¢¸ÃÎó²î £¬£¬£¬£¬½øÒ»²½µ¼ÖÂϵͳȨÏÞ±»¶ñÒâ»ñÈ¡¡£¡£Îó²îÆÀ·Ö7.3·Ö £¬£¬£¬£¬Îó²îÆ·¼¶¸ßΣ¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


Notepad++ v8.8.1


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


¿ª·¢ÍŶÓÒÑÔÚ v8.8.2 °æ±¾ÖÐÐÞ¸´Á˸ÃÎó²î¡£¡£
ÏÂÔØÁ´½Ó£º
Notepad++ ¹Ù·½ÍøÕ¾ÉÐδÐû²¼ v8.8.2 µÄÕýʽ°æ±¾¡£¡£ÏÖÔÚ¿ÉÓõÄ×îÐÂÕýʽ°æ±¾ÊÇ v8.8.1¡£¡£ÈôÊÇÄúÏ£ÍûʵÑé v8.8.2 µÄÔ¤Ðû²¼°æ±¾£¨Release Candidate£© £¬£¬£¬£¬¿ÉÒÔͨ¹ýÒÔÏÂÁ´½ÓÏÂÔØ
http://download.notepad-plus-plus.org/repository/8.x/8.8.2.RC2/


3.2 ÔÝʱ²½·¥


ÔÝÎÞ¡£¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡ £¬£¬£¬£¬ïÔ̭ϵͳÎó²î £¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ £¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ £¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ £¬£¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø £¬£¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ· £¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí £¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò £¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£


3.4 ²Î¿¼Á´½Ó


https://drive.google.com/drive/folders/11yeUSWgqHvt4Bz5jO3ilRRfcpQZ6Gvpn
https://github.com/notepad-plus-plus/notepad-plus-plus/commit/f2346ea00d5b4d907ed39d8726b38d77c8198f30
https://github.com/notepad-plus-plus/notepad-plus-plus/security/advisories/GHSA-9vx8-v79m-6m24
https://nvd.nist.gov/vuln/detail/CVE-2025-49144