¡¾Îó²îͨ¸æ¡¿Notepad++ v8.8.1×°ÖóÌÐòÌØÈ¨ÌáÉýÎó²î (CVE-2025-49144)

Ðû²¼Ê±¼ä 2025-06-24

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

Notepad++ v8.8.×°ÖóÌÐòÌØÈ¨ÌáÉýÎó²î

CVE   ID

CVE-2025-49144

Îó²îÀàÐÍ

ÌØÈ¨ÌáÉýÎó²î

·¢Ã÷ʱ¼ä

2025-06-24

Îó²îÆÀ·Ö

7.3

Îó²îÆ·¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍâµØ

ËùÐèȨÏÞ

µÍ

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

ÐèÒª

PoC/EXP

ÒѹûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


Notepad++ÊÇÒ»¿îÃâ·ÑµÄ¿ªÔ´Îı¾±à¼­Æ÷£¬£¬£¬£¬£¬£¬Ö§³Ö¶àÖÖ±à³ÌÓïÑÔµÄÓï·¨¸ßÁÁºÍ×Ô¶¯Íê³É¡£¡£¡£¡£¡£Ëü»ùÓÚScintilla±à¼­¿Ø¼þ£¬£¬£¬£¬£¬£¬ÌṩǿʢµÄ¹¦Ð§£¬£¬£¬£¬£¬£¬Èç¶à±êǩҳ±à¼­¡¢ÕýÔò±í´ïʽËÑË÷Ìæ»»¡¢²å¼þÀ©Õ¹ºÍ×Ô½ç˵¿ì½Ý¼üµÈ¡£¡£¡£¡£¡£Notepad++ÊÊÓÃÓÚWindowsϵͳ£¬£¬£¬£¬£¬£¬ÆÕ±éÓÃÓÚ±à³Ì¡¢¾ç±¾±à¼­ÒÔ¼°Ò»Ñùƽ³£Îı¾´¦Öóͷ£¡£¡£¡£¡£¡£ÒÀ¸½ÆäÇáÁ¿¼¶ºÍ¸ßЧÐÔ£¬£¬£¬£¬£¬£¬³ÉΪ¿ª·¢ÕߺÍÊÖÒÕÖ°Ô±µÄ³£Óù¤¾ß¡£¡£¡£¡£¡£


2025Äê6ÔÂ24ÈÕ£¬£¬£¬£¬£¬£¬°ÙÀÖ²©¼¯ÍÅVSRC¼à²âµ½notepad-plus-plusÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬Åû¶ÁËÒ»¸öÌØÈ¨ÌáÉýÎó²î¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓò»ÊÜ¿ØÖƵĿÉÖ´ÐÐÎļþËÑË÷·¾¶£¨EXE/DLLËÑË÷·¾¶£©ÔÚ×°ÖÃÀú³ÌÖУ¬£¬£¬£¬£¬£¬½«¶ñÒâ¿ÉÖ´ÐÐÎļþ¼ÓÔØÎªSYSTEMȨÏÞ£¬£¬£¬£¬£¬£¬´Ó¶øÊµÏÖÍâµØÌØÈ¨ÌáÉý¡£¡£¡£¡£¡£Îó²îµÄPOCÒѹûÕæ£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýÌØ¶¨µÄÎļþ·¾¶²Ù×÷´¥·¢¸ÃÎó²î£¬£¬£¬£¬£¬£¬½øÒ»²½µ¼ÖÂϵͳȨÏÞ±»¶ñÒâ»ñÈ¡¡£¡£¡£¡£¡£Îó²îÆÀ·Ö7.3·Ö£¬£¬£¬£¬£¬£¬Îó²îÆ·¼¶¸ßΣ¡£¡£¡£¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


Notepad++ v8.8.1


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


¿ª·¢ÍŶÓÒÑÔÚ v8.8.2 °æ±¾ÖÐÐÞ¸´Á˸ÃÎó²î¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
Notepad++ ¹Ù·½ÍøÕ¾ÉÐδÐû²¼ v8.8.2 µÄÕýʽ°æ±¾¡£¡£¡£¡£¡£ÏÖÔÚ¿ÉÓõÄ×îÐÂÕýʽ°æ±¾ÊÇ v8.8.1¡£¡£¡£¡£¡£ÈôÊÇÄúÏ£ÍûʵÑé v8.8.2 µÄÔ¤Ðû²¼°æ±¾£¨Release Candidate£©£¬£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ýÒÔÏÂÁ´½ÓÏÂÔØ
http://download.notepad-plus-plus.org/repository/8.x/8.8.2.RC2/


3.2 ÔÝʱ²½·¥


ÔÝÎÞ¡£¡£¡£¡£¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£¡£¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://drive.google.com/drive/folders/11yeUSWgqHvt4Bz5jO3ilRRfcpQZ6Gvpn
https://github.com/notepad-plus-plus/notepad-plus-plus/commit/f2346ea00d5b4d907ed39d8726b38d77c8198f30
https://github.com/notepad-plus-plus/notepad-plus-plus/security/advisories/GHSA-9vx8-v79m-6m24
https://nvd.nist.gov/vuln/detail/CVE-2025-49144