¡¾·ì϶¹«¸æ¡¿OpenVPN DCOÇý¶¯·¨Ê½»º³åÇøÒç¶Âí½Å (CVE-2025-50054)

°ä²¼¹¦·ò 2025-06-23

Ò»¡¢·ì϶¸ÅÊö


·ìϼûû³Æ

OpenVPN DCOÇý¶¯·¨Ê½»º³åÇøÒç¶Âí½Å

CVE   ID

CVE-2025-50054

·ì϶ÀàÐÍ

»º³åÇøÒç¶Âí½Å

·¢ÏÖ¹¦·ò

2025-06-23

·ì϶ÆÀ·Ö

9.8

·ì϶µÈ¼¶

ÑϳÁ

¹¥»÷ÏòÁ¿

±¾µØ

ËùÐèȨÏÞ

µÍ

ÀûÓÃÄѶÈ

µÍ

Óû§½»»¥

²»±ØÒª

PoC/EXP

δ¹«¿ª

ÔÚÒ°ÀûÓÃ

δ·¢ÏÖ


OpenVPNÊÇÒ»¿î¿ªÔ´µÄÐé¹¹¸öÈËÍøÂ磨VPN£©Èí¼þ£¬ÀûÓÃSSL/TLSºÍ̸ʵÏÖ¼ÓÃÜͨѶ£¬Ö§³Öµã¶ÔµãºÍÕ¾µãµ½Õ¾µãµÄ°²È«ÏνÓ£¬¿í·ºÀûÓÃÓÚÔ¶³Ì½Ó¼ûºÍÆóÒµÍøÂç¡£ËüÖ§³Ö¶àÖÖÉí·ÝÑéÖ¤·½Ê½£¬Ô̺¬Ô¤¹²ÏíÃÜÔ¿¡¢Êý×ÖÖ¤ÊéºÍÓû§Ãû/ÃÜÂë×éºÏ¡£Í¨¹ýʹÓÃOpenSSL¼ÓÃܿ⣬OpenVPNÌṩ¸ß´ï256λµÄ¼ÓÃÜÇ¿¶È£¬²¢Ö§³ÖÃÀÂúǰÏò±£ÃÜ£¨PFS£©Ö°ÄÜ£¬¼ÓÇ¿Êý¾Ý°²È«ÐÔ¡£OpenVPN¼æÈݶàÖÖ²Ù×÷ϵͳ£¬ÈçWindows¡¢Linux¡¢macOS¡¢iOSºÍAndroid£¬ºÏÓÃÓÚ¼ÒÍ¥Óû§¡¢ÆóÒµºÍ¿ª·¢Õߣ¬ÒòÆä¸ß°²È«ÐÔ¡¢½Ã½ÝÐԺͿªÔ´¸öÐÔ£¬³ÉΪȫÇò×îÊÜÓ­½ÓµÄVPN½â¾ö¹æ»®Ö®Ò»¡£


2025Äê6ÔÂ23ÈÕ£¬±¦ÔËÀ³¹Ù·½ÍøÕ¾¼¯ÍÅVSRC¼à²âµ½openvpn°ä²¼°²È«²¼¸æ£¬Åû¶openvpnÖеÄÒ»¸ö»º³åÇøÒç¶Âí½Å¡£¸Ã·ì϶´æÔÚÓÚOpenVPNµÄWindowsÊý¾ÝÍ¨Â·Ð¶ÔØÇý¶¯·¨Ê½£¨ovpn-dco-win£©ÖУ¬µ±Óû§¿Õ¼ä¹ý³ÌÏòÄÚºËÇý¶¯·¨Ê½·¢Ëͳ¬¹ý1500×ֽڵĽÚÔìÐÂÎÅʱ£¬»áµ¼ÖÂWindows DCOÇý¶¯·¨Ê½±ÀÀ£¡£´Ë·ì϶½öÄÜͨ¹ý±¾µØ¹ý³Ì´¥·¢£¬¶ø·ÇÔ¶³Ì¹¥»÷£¬ÇÒ¼´±ã³¤¶ÌÌØÈ¨¹ý³ÌÒ²ÄÜÀûÓô˷ì϶¡£OpenVPN×ÔÉíÓµÓÐÏÞ¶È£¬²»»á·¢Ëͳ¬³¤ÐÂÎÅ£¬µ«×Ô½ç˵±àÒëµÄOpenVPN»òÆäËûÓëDCOÇý¶¯·¨Ê½½»»¥µÄ¹ý³Ì¿ÉÄÜÈÆ¹ý¸ÃÏÞ¶È£¬´¥·¢·ì϶¡£¸Ã·ì϶¿ÉÄܵ¼ÖÂϵͳ²»²»±ä¡£


¶þ¡¢Ó°ÏìÁìÓò


ovpn-dco-win ¡Ü 1.3.0
2.6.0-I005 ¡Ü OpenVPN GUI for Windows ¡Ü 2.6.14-I001
OpenVPN GUI for Windows = 2.7_alpha1-I001


Èý¡¢°²È«´ëÊ©


3.1 Éý¼¶°æ±¾


½¨ÒéÉý¼¶OpenVPN GUI for WindowsÖÁÈçϰ汾
OpenVPN GUI for Windows ¡Ý 2.6.14-I002
OpenVPN GUI for Windows ¡Ý 2.7_alpha2-I001¡£


ÏÂÔØÁ´½Ó£ºhttps://openvpn.net/community-downloads/


3.2 һʱ´ëÊ©


ÔÝÎÞ¡£


3.3 ͨÓý¨Òé


?¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£
?¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ¡£
?ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£
?¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£
?ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£


3.4 ²Î¿¼Á´½Ó


https://community.openvpn.net/Security%20Announcements/CVE-2025-50054
https://nvd.nist.gov/vuln/detail/CVE-2025-50054