目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2025-55188 PoC — 7-Zip 安全漏洞

来源
关联漏洞
标题: 7-Zip 安全漏洞 (CVE-2025-55188)
Description:7-Zip是7-Zip开源的一个压缩软件。 7-Zip 25.01之前版本存在安全漏洞,该漏洞源于解压时未正确处理符号链接。
Description
7z exploit POC versions prior to 25.01
介绍
# CVE-2025-55188-7z-exploit
---

# 7-Zip Symlink Arbitrary File Write PoC (CVE-2025-55188)

## Description

This proof-of-concept demonstrates **CVE-2025-55188**, a vulnerability in 7-Zip versions prior to **25.01**.
The flaw occurs because 7-Zip does not properly handle **symbolic links** during extraction, allowing a crafted archive to overwrite arbitrary files on the target system.

If a victim extracts a malicious archive, the attacker can:

* Overwrite sensitive files (e.g., `.bashrc`, `~/.ssh/authorized_keys`, configuration files).
* Potentially gain code execution or unauthorized access.

---

## How it Works

1. An attacker creates a symbolic link pointing to a target file outside the extraction directory.
2. The link is added to a tar archive along with a payload file.
3. When the archive is extracted with a vulnerable version of 7-Zip, the symlink is followed, and the payload overwrites the target file.

---

## Requirements

* **7-Zip** version **older than 25.01**.
* Target must extract the archive with `7z x` or a vulnerable extraction tool.
* The extraction location must allow symlink traversal to the intended target file.

---

## Usage

```bash
./exploit.sh <payload-file> <symlink-target> <output-archive>
```

* **payload-file**: File containing the malicious content to write.
* **symlink-target**: Path to the file you want to overwrite (e.g., `../../.ssh/authorized_keys`).
* **output-archive**: Name of the crafted `.7z` archive.

Example:

```bash
./exploit.sh mykey.pub ../../.ssh/authorized_keys exploit.7z
```

---

## Disclaimer

This PoC is provided **for educational and testing purposes only**.
Do not use it on systems you do not own or have explicit permission to test.
Unauthorized use may violate laws and result in criminal or civil penalties.

---
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →