钉钉 RCE 漏洞

钉钉 RCE 漏洞

影响版本

版本:6.3.5

https://dtapp-pub.dingtalk.com/dingtalk-desktop/win_installer/Release/DingTalk_v6.3.5.11308701.exe

触发方式

dingtalk://dingtalkclient/page/link?url=127.0.0.1/test.html&pc_slide=true

image-20220216141703274

成功复现

image-20220216141616222

POC

参考https://github.com/crazy0x70/dingtalk-RCE

修复方法

升级最新版 6.3.25

猜你喜欢

转载自blog.csdn.net/god_zzZ/article/details/122962775