¡¾Îó²îͨ¸æ¡¿Notepad++ v8.8.1×°ÖóÌÐòÌØÈ¨ÌáÉýÎó²î (CVE-2025-49144)

Ðû²¼Ê±¼ä 2025-06-24

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

Notepad++ v8.8.×°ÖóÌÐòÌØÈ¨ÌáÉýÎó²î

CVE   ID

CVE-2025-49144

Îó²îÀàÐÍ

ÌØÈ¨ÌáÉýÎó²î

·¢Ã÷ʱ¼ä

2025-06-24

Îó²îÆÀ·Ö

7.3

Îó²îÆ·¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍâµØ

ËùÐèȨÏÞ

µÍ

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

ÐèÒª

PoC/EXP

ÒѹûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


Notepad++ÊÇÒ»¿îÃâ·ÑµÄ¿ªÔ´Îı¾±à¼­Æ÷£¬Ö§³Ö¶àÖÖ±à³ÌÓïÑÔµÄÓï·¨¸ßÁÁºÍ×Ô¶¯Íê³É¡£Ëü»ùÓÚScintilla±à¼­¿Ø¼þ£¬ÌṩǿʢµÄ¹¦Ð§£¬Èç¶à±êǩҳ±à¼­¡¢ÕýÔò±í´ïʽËÑË÷Ìæ»»¡¢²å¼þÀ©Õ¹ºÍ×Ô½ç˵¿ì½Ý¼üµÈ¡£Notepad++ÊÊÓÃÓÚWindowsϵͳ£¬ÆÕ±éÓÃÓÚ±à³Ì¡¢¾ç±¾±à¼­ÒÔ¼°Ò»Ñùƽ³£Îı¾´¦Öóͷ£¡£ÒÀ¸½ÆäÇáÁ¿¼¶ºÍ¸ßЧÐÔ£¬³ÉΪ¿ª·¢ÕߺÍÊÖÒÕÖ°Ô±µÄ³£Óù¤¾ß¡£


2025Äê6ÔÂ24ÈÕ£¬×ðÁú¿­Ê±¼¯ÍÅVSRC¼à²âµ½notepad-plus-plusÐû²¼Ç徲ͨ¸æ£¬Åû¶ÁËÒ»¸öÌØÈ¨ÌáÉýÎó²î¡£¹¥»÷Õß¿ÉʹÓò»ÊÜ¿ØÖƵĿÉÖ´ÐÐÎļþËÑË÷·¾¶£¨EXE/DLLËÑË÷·¾¶£©ÔÚ×°ÖÃÀú³ÌÖУ¬½«¶ñÒâ¿ÉÖ´ÐÐÎļþ¼ÓÔØÎªSYSTEMȨÏÞ£¬´Ó¶øÊµÏÖÍâµØÌØÈ¨ÌáÉý¡£Îó²îµÄPOCÒѹûÕæ£¬¹¥»÷Õß¿Éͨ¹ýÌØ¶¨µÄÎļþ·¾¶²Ù×÷´¥·¢¸ÃÎó²î£¬½øÒ»²½µ¼ÖÂϵͳȨÏÞ±»¶ñÒâ»ñÈ¡¡£Îó²îÆÀ·Ö7.3·Ö£¬Îó²îÆ·¼¶¸ßΣ¡£


¶þ¡¢Ó°Ïì¹æÄ£


Notepad++ v8.8.1


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


¿ª·¢ÍŶÓÒÑÔÚ v8.8.2 °æ±¾ÖÐÐÞ¸´Á˸ÃÎó²î¡£
ÏÂÔØÁ´½Ó£º
Notepad++ ¹Ù·½ÍøÕ¾ÉÐδÐû²¼ v8.8.2 µÄÕýʽ°æ±¾¡£ÏÖÔÚ¿ÉÓõÄ×îÐÂÕýʽ°æ±¾ÊÇ v8.8.1¡£ÈôÊÇÄúÏ£ÍûʵÑé v8.8.2 µÄÔ¤Ðû²¼°æ±¾£¨Release Candidate£©£¬¿ÉÒÔͨ¹ýÒÔÏÂÁ´½ÓÏÂÔØ
http://download.notepad-plus-plus.org/repository/8.x/8.8.2.RC2/


3.2 ÔÝʱ²½·¥


ÔÝÎÞ¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬ïÔ̭ϵͳÎó²î£¬ÌáÉý·þÎñÆ÷µÄÇå¾²ÐÔ¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬Ð޸ķÀ»ðǽսÂÔ£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬ïÔÌ­½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬ïÔÌ­¹¥»÷Ãæ¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£


3.4 ²Î¿¼Á´½Ó


https://drive.google.com/drive/folders/11yeUSWgqHvt4Bz5jO3ilRRfcpQZ6Gvpn
https://github.com/notepad-plus-plus/notepad-plus-plus/commit/f2346ea00d5b4d907ed39d8726b38d77c8198f30
https://github.com/notepad-plus-plus/notepad-plus-plus/security/advisories/GHSA-9vx8-v79m-6m24
https://nvd.nist.gov/vuln/detail/CVE-2025-49144