DingTalk RCE Vulnerability

DingTalk RCE Vulnerability

Affected version

Version: 6.3.5

https://dtapp-pub.dingtalk.com/dingtalk-desktop/win_installer/Release/DingTalk_v6.3.5.11308701.exe

trigger method

dingtalk://dingtalkclient/page/link?url=127.0.0.1/test.html&pc_slide=true

image-20220216141703274

Successfully reproduced

image-20220216141616222

POC

Reference https://github.com/crazy0x70/dingtalk-RCE

Repair method

Upgrade to the latest version 6.3.25

Guess you like

Origin blog.csdn.net/god_zzZ/article/details/122962775