Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Notepad++ DLL Ð®ÖÆÎó²î |
CVE ID | CVE-2025-56383 |
Îó²îÀàÐÍ | DLL Ð®ÖÆ | ·¢Ã÷ʱ¼ä | 2025-09-30 |
Îó²îÆÀ·Ö | 8.4 | Îó²îÆ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍâµØ | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
Notepad++ÊÇÒ»¿î¿ªÔ´µÄÎı¾±à¼Æ÷£¬£¬£¬£¬£¬£¬ÆÕ±éÓÃÓÚ´úÂë±àдºÍÎı¾´¦Öóͷ£¡£¡£ËüÖ§³Ö¶àÖÖ±à³ÌÓïÑÔºÍÎļþÃûÌ㬣¬£¬£¬£¬£¬¾ßÓÐÓï·¨¸ßÁÁ¡¢×Ô¶¯Íê³É¡¢ÕýÔò±í´ïʽËÑË÷µÈ¹¦Ð§¡£¡£Notepad++ÒÔÆäÇáÁ¿¼¶¡¢¸ßЧ¡¢¿ÉÀ©Õ¹ÐÔÇ¿µÄÌØµã£¬£¬£¬£¬£¬£¬ÉîÊÜ¿ª·¢ÕߺÍÊÖÒÕÖ°Ô±µÄϲ»¶¡£¡£
2025Äê9ÔÂ30ÈÕ£¬£¬£¬£¬£¬£¬ÄϹ¬NGÓéÀÖ¼¯ÍÅVSRC¼à²âµ½Ò»¸ö±£´æÓÚNotepad++ÖеÄDLLÐ®ÖÆÎó²î£¬£¬£¬£¬£¬£¬¸ÃÎó²îÔÊÐí¹¥»÷ÕßÌæ»»Õýµ±µÄ²å¼þÎļþ£¬£¬£¬£¬£¬£¬½ø¶øÔÚÿ´ÎÆô¶¯Notepad++ʱ¶¼ÄÜÖ´ÐжñÒâ´úÂë¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý½«¶ñÒâDLLÎļþ£¨ÈçNppExport.dll£©Ìæ»»ÔʼµÄ²å¼þDLL£¬£¬£¬£¬£¬£¬´Ó¶øÔÚ²»Ó°ÏìÓ¦ÓóÌÐòÕý³£¹¦Ð§µÄÇéÐÎÏ£¬£¬£¬£¬£¬£¬Ö´ÐжñÒâ´úÂë¡£¡£ÎªÁ˼á³Ö¹¦Ð§µÄÕý³£ÔËÐУ¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔ½«ÔʼDLLÖØÃüÃû£¨ÀýÈ磬£¬£¬£¬£¬£¬original-NppExport.dll£©£¬£¬£¬£¬£¬£¬²¢ÉèÖÃαÔìµÄDLLÎļþÊðÀíÕýµ±µÄ¹¦Ð§Å²Ó㬣¬£¬£¬£¬£¬È·±£Óû§²»²ì¾õ£¬£¬£¬£¬£¬£¬µ«¶ñÒâ´úÂëÔÚºǫִ́ÐС£¡£ÕâÖÖ¹¥»÷·½·¨¿ÉÄܵ¼ÖÂÌØÈ¨ÌáÉý¡¢³¤ÆÚÐÔÖ²Èë»ò½øÒ»²½µÄ¶ñÒâÈí¼þ°²ÅÅ¡£¡£¡£¡£Îó²îÆÀ·Ö8.4£¬£¬£¬£¬£¬£¬Îó²î¼¶±ð¸ßΣ¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
Notepad++ <= 8.8.3
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
Éý¼¶ÖÁ¹Ù·½×îа汾£¨8.8.4¼°ÒÔÉÏ£©£¬£¬£¬£¬£¬£¬ÒÔÐÞ¸´¸ÃÎó²î¡£¡£
ÏÂÔØÁ´½Ó£ºhttps://github.com/notepad-plus-plus/notepad-plus-plus/releases/
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£
3.3 ͨÓý¨Òé
? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¡£¬£¬£¬£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£? ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£? ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£? ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£
3.4 ²Î¿¼Á´½Ó
https://github.com/notepad-plus-plus/notepad-plus-plus/https://github.com/zer0t0/CVE-2025-56383-Proof-of-Concepthttps://nvd.nist.gov/vuln/detail/CVE-2025-56383