钉钉 RCE 漏洞
钉钉 RCE 漏洞
影响版本
版本:6.3.5
https://dtapp-pub.dingtalk.com/dingtalk-desktop/win\_installer/Release/DingTalk\_v6.3.5.11308701.exe
触发方式
1 | dingtalk://dingtalkclient/page/link?url=127.0.0.1/test.html&pc_slide=true |
成功复现
POC
参考https://github.com/crazy0x70/dingtalk-RCE
修复方法
升级最新版 6.3.25
All articles in this blog are licensed under CC BY-NC-SA 4.0 unless stating additionally.