avatar
Articles
145
Tags
55
Categories
12

Home
Archives
Categories
List
  • Music
  • Movie
About
Zeo's Blog
Home
Archives
Categories
List
  • Music
  • Movie
About

钉钉 RCE 漏洞

Created2022-02-16|Updated2025-08-31|WEB 漏洞复现和分析

钉钉 RCE 漏洞

影响版本

版本:6.3.5

https://dtapp-pub.dingtalk.com/dingtalk-desktop/win\_installer/Release/DingTalk\_v6.3.5.11308701.exe

触发方式

1
dingtalk://dingtalkclient/page/link?url=127.0.0.1/test.html&pc_slide=true

image-20220216141703274

成功复现

image-20220216141616222

POC

参考https://github.com/crazy0x70/dingtalk-RCE

修复方法

升级最新版 6.3.25

Author: Zeo
Link: https://zeo.plus/posts/%E9%92%89%E9%92%89%20RCE%20%E6%BC%8F%E6%B4%9E.html
Copyright Notice: All articles in this blog are licensed under CC BY-NC-SA 4.0 unless stating additionally.
安全 web安全
cover of previous post
Previous Post
反爬虫SSL TLS指纹识别和绕过JA3算法.md
cover of next post
Next Post
Spring Boot Actuator 漏洞复现合集
avatar
Zeo
Articles
145
Tags
55
Categories
12
Follow Me
Announcement
Weclome my blog
Catalog
  1. 1. 钉钉 RCE 漏洞
    1. 1.1. 影响版本
    2. 1.2. 触发方式
    3. 1.3. 成功复现
    4. 1.4. POC
    5. 1.5. 修复方法
Recent Post
利用mcp sqlmap 验证漏洞
利用mcp sqlmap 验证漏洞2025-08-31
9 如果评估微调过程
9 如果评估微调过程2025-07-13
8 模型微调-关键超参数
8 模型微调-关键超参数2025-07-06
MCP 服务开发到发布
MCP 服务开发到发布2025-06-29
7 微调 黑盒蒸馏 突破伦理限制
7 微调 黑盒蒸馏 突破伦理限制2025-04-26
©2019 - 2025 By Zeo
Hi, welcome to my blog!