ื”ืขื“ื›ื•ืŸ ืฉืืชื ืœื ื™ื›ื•ืœื™ื ืœื”ืจืฉื•ืช ืœืขืฆืžื›ื ืœื“ืœื’ ืขืœื™ื•: ืกื•ืฃ ื”ืชืžื™ื›ื” ื‘-Office 2016 ื•-Office 2019

ืงืจื ืขื›ืฉื™ื•
ืื ื• ืžืฉืชืžืฉื™ื ื‘ื‘ื™ื ื” ืžืœืื›ื•ืชื™ืช ืœืชืจื’ื•ื ื”ืืชืจ, ื•ืขืœ ืืฃ ืฉืื ื• ืฉื•ืืคื™ื ืœื“ื™ื•ืง ืžืจื‘ื™, ื™ื™ืชื›ืŸ ืฉื”ืชืจื’ื•ืžื™ื ืื™ื ื ืžื“ื•ื™ืงื™ื ื‘ืžืืช ื”ืื—ื•ื–ื™ื. ืื ื• ืžื•ื“ื™ื ืœืš ืขืœ ื”ื”ื‘ื ื”.

ืคื’ื™ืขื•ืช ืงืจื™ื˜ื™ืช ื‘-Apache Tika XXE: 3 ืฉื›ื‘ื•ืช ื”ื’ื ื” ืžืขื‘ืจ ืœืชื™ืงื•ืŸ CVE-2025-66516

ืขึทืœ ื™ึฐื“ึตื™ OPSWAT
ืฉืชืฃ ืืช ื”ืคื•ืกื˜ ื”ื–ื”

CVE-2025-66516, ืฉื”ืชื’ืœื” ืœืจืืฉื•ื ื” ื‘-4 ื‘ื“ืฆืžื‘ืจ 2025, ื”ื™ื ืคื’ื™ืขื•ืช ืงืจื™ื˜ื™ืช ( ืฆื™ื•ืŸ ื—ื•ืžืจื” 9.8 ืขืœ ื™ื“ื™ NVD ) ื‘-Apache Tika, ื”ืžื“ื’ื™ืฉื” ืืช ื”ื”ืฉืคืขื” ื”ื—ืจื™ื’ื” ืฉื™ื›ื•ืœื” ืœื”ื™ื•ืช ืœืคื’ื ื‘ื•ื“ื“ ื‘ืจื›ื™ื‘ backend ื ืคื•ืฅ ืขืœ ืคื ื™ ื™ื™ืฉื•ืžื™ื ืžื•ื“ืจื ื™ื™ื. Apache Tika ืžื•ื˜ืžืข ืขืžื•ืง ื‘ื–ืจื™ืžื•ืช ืขื‘ื•ื“ื” ืฉืœ ืขื™ื‘ื•ื“ ืžืกืžื›ื™ื (PDF, PPT, XLS) ืœืฆื•ืจืš ืื™ื ื“ื•ืงืก, ื—ื™ืคื•ืฉ, ืชืื™ืžื•ืช ื•ื ื™ืชื•ื— ืชื•ื›ืŸ, ื•ืœืขืชื™ื ืงืจื•ื‘ื•ืช ืคื•ืขืœ ืžืื—ื•ืจื™ ื”ืงืœืขื™ื ืขื ื’ื™ืฉื” ืจื—ื‘ื” ืœืžืขืจื›ื•ืช ื•ื ืชื•ื ื™ื. ื›ืืฉืจ ืคื’ื™ืขื•ืช ืฆืฆื” ื‘ืฉื›ื‘ื” ื–ื•, ื”ื™ื ืขืœื•ืœื” ืœืกื›ืŸ ืกื‘ื™ื‘ื•ืช ืฉืœืžื•ืช, ื’ื ืื ื”ืกืคืจื™ื™ื” ื”ืžื•ืฉืคืขืช ืื™ื ื” ื—ืฉื•ืคื” ื™ืฉื™ืจื•ืช ืœืžืฉืชืžืฉื™ ื”ืงืฆื”.

ืžืงื•ืจ: NVD

ื”ืกืชืžื›ื•ืช ืขืœ ืชื™ืงื•ื ื™ื ื‘ืœื‘ื“ ืื™ื ื” ืขื•ื“ ื”ื’ื ื” ืžืกืคืงืช ืžืคื ื™ ื ื™ืฆื•ืœ ืœืจืขื” ืงืจื™ื˜ื™ ืžืกื•ื’ ื–ื”. ืืจื’ื•ื ื™ื ื–ืงื•ืงื™ื ืœื’ื™ืฉืช ืื‘ื˜ื—ื” ืจื‘-ืฉื›ื‘ืชื™ืช ื”ืžื ื™ื—ื” ืฉืคื’ื™ืขื•ื™ื•ืช ื™ืชืจื—ืฉื• ื•ืžืชืžืงื“ืช ื‘ื”ืคื—ืชืช ื”ื—ืฉื™ืคื” ื‘ื›ืœ ืฉืœื‘.

ื‘ื‘ืœื•ื’ ื–ื” ื ื‘ื—ืŸ ืฉืœื•ืฉ ืฉื›ื‘ื•ืช ืžืฉืœื™ืžื•ืช:

  1. ื ื™ืงื•ื™ ืงื‘ืฆื™ PDF ืœื ืžื”ื™ืžื ื™ื ืœืคื ื™ ืขื™ื‘ื•ื“ื Deep CDR
  2. ื–ื™ื”ื•ื™ ื”ืชื ื”ื’ื•ืช ื–ื“ื•ื ื™ืช ืฉืœ ืžืกืžื›ื™ื ื‘ืืžืฆืขื•ืช ื ื™ืชื•ื— ืžืชืงื“ื ืขื ื–ื™ื”ื•ื™ ื™ื•ื ืืคืก
  3. ืื‘ื˜ื—ืช ืฉืจืฉืจืช ื”ืืกืคืงื” โ€‹โ€‹ืฉืœ ื”ืชื•ื›ื ื” ืœื’ื™ืœื•ื™ ืคื’ื™ืขื•ื™ื•ืช ืงืจื™ื˜ื™ื•ืช ื‘-XXE ื‘ืชืœื•ื™ื•ืช Apache Tika ื‘ืืžืฆืขื•ืช SBOM (ืจืฉื™ืžืช ื—ื•ืžืจื™ื ืฉืœ ืชื•ื›ื ื”) ื•-SCA (ื ื™ืชื•ื— ื”ืจื›ื‘ ืชื•ื›ื ื”).

ื™ื—ื“, ืฉื›ื‘ื•ืช ืืœื• ืžืกืคืงื•ืช ืืกื˜ืจื˜ื’ื™ื™ืช ื”ื’ื ื” ืžืขืžื™ืงื” ื•ืžืขืฉื™ืช ืœื”ืคื—ืชืช ืคื’ื™ืขื•ื™ื•ืช ื™ื“ื•ืขื•ืช ื•ืื™ื•ืžื™ื ืขืชื™ื“ื™ื™ื ืžื‘ื•ืกืกื™ ืงื‘ืฆื™ื.

1. ื ื™ืงื•ื™ ืงื‘ืฆื™ื ื‘ืืžืฆืขื•ืช Deep CDR โ„ข

ืคืชืจื•ืŸ ื˜ืงื˜ื™ ืœืฆืžืฆื•ื ืคื’ื™ืขื” ื‘-CVE-2025-66516 ื”ื•ื ื ื™ืงื•ื™ ื›ืœ ืงื‘ืฆื™ ื”-PDF ื”ื ื›ื ืกื™ื ืœืคื ื™ ืฉื”ื ืžื’ื™ืขื™ื ืœ-Apache Tika. Deep CDR ( OPSWAT (ื˜ื›ื ื•ืœื•ื’ื™ื™ืช ื ื˜ืจื•ืœ ื•ืฉื—ื–ื•ืจ ืชื•ื›ืŸ ืฉืœ) ืžืกื™ืจื” ื˜ืคืกื™ XFA ืžื•ื˜ืžืขื™ื, ื”ืคื ื™ื•ืช ืœื™ืฉื•ื™ื•ืช ื—ื™ืฆื•ื ื™ื•ืช ื•ื›ืœ ืชื•ื›ืŸ ืคืขื™ืœ ืื—ืจ ืฉืขืœื•ืœ ืœื”ืคืขื™ืœ ื”ืชืงืคื•ืช XXE.

ื”ืคืœื˜ ืฉืขื‘ืจ ื ื™ืงื•ื™ ื”ื•ื ืงื•ื‘ืฅ PDF ื‘ื˜ื•ื— ื•ืžื—ื•ื“ืฉ ื”ืžื›ื™ืœ ืจืง ืืช ื”ืืœืžื ื˜ื™ื ืฉืื•ืฉืจื• ื•ืœื ื ื™ืชื ื™ื ืœื”ืคืขืœื”. ืฉื›ื‘ืช ืขื™ื‘ื•ื“ ืžืงื“ื™ื ื–ื• ืžื‘ื˜ื™ื—ื” ืฉื’ื ืงื‘ืฆื™ PDF ืฉื ื•ืฆืจื• ื‘ืื•ืคืŸ ื–ื“ื•ื ื™ ื™ื ื•ื˜ืจืœื• ืœืคื ื™ ืฉ-Tika ืžื‘ืฆืขืช ื ื™ืชื•ื— ืื• ื—ื™ืœื•ืฅ ืžื˜ื-ื ืชื•ื ื™ื. ืœืžื™ื“ืข ื ื•ืกืฃ ืขืœ OPSWAT Deep CDR

ื”ืกืจืช ื˜ื•ืคืก XFA ืขืœ ื™ื“ื™ Deep CDR
ื“ื•ื•ื— ืขืœ ืกืงืจื™ืคื˜ื™ื ื‘ื˜ื•ืคืก XFA

2. ื ื™ืชื•ื— ื”ืชื ื”ื’ื•ืชื™ ืขื ื–ื™ื”ื•ื™ ื™ื•ื ืืคืก

ืขืœ ื™ื“ื™ ืฉื™ืœื•ื‘ ืฉืœ ื›ืœืœื™ ื–ื™ื”ื•ื™ ืžืชืงื“ืžื™ื ืขื ื”ื“ืžื™ื™ืช ื–ืžืŸ ืจื™ืฆื”, OPSWAT ื˜ื›ื ื•ืœื•ื’ื™ื™ืช ืืจื’ื– ื”ื—ื•ืœ ื”ืงื ื™ื™ื ื™ืช ืฉืœ Filescan, ื”ืžื‘ื•ืกืกืช ืขืœ ืืžื•ืœืฆื™ื”, ื™ื›ื•ืœื” ืœื–ื”ื•ืช ื”ืชื ื”ื’ื•ืช ื–ื“ื•ื ื™ืช ืฉื ื™ืชื•ื— ืกื˜ื˜ื™ ืขืœื•ืœ ืœืคืกืคืก, ืืคื™ืœื• ื›ืืฉืจ ืคืจืฆื•ืช ื’ื™ืฉื” ืžื˜ื•ืฉื˜ืฉื•ืช ืื• ืžื•ื˜ืžืขื•ืช ื‘ืžื‘ื ื™ ืงื‘ืฆื™ื ืžื•ืจื›ื‘ื™ื. ื‘ื“ื•ืง ืืช ื”ืคืจื˜ื™ื ื‘- Filescan .IO - ืคืœื˜ืคื•ืจืžืช ื ื™ืชื•ื— ืชื•ื›ื ื•ืช ื–ื“ื•ื ื™ื•ืช ืžื”ื“ื•ืจ ื”ื‘ื .

ื’ื™ืœื•ื™ ืคื’ื™ืขื•ื™ื•ืช ืื• ืชื™ืงื•ื ื™ ืกืคืงื™ื ืœืขื™ืชื™ื ืงืจื•ื‘ื•ืช ืื™ื ื ืžืฆืœื™ื—ื™ื ืœืขืžื•ื“ ื‘ืงืฆื‘ ืฉืœ ื”ืชืงืคื•ืช ื™ื•ื ืืคืก; OPSWAT ืžืžื ืคืช ื ื™ืชื•ื— ื“ื™ื ืžื™ ืขื ืžื•ื“ื™ืขื™ืŸ ืื™ื•ืžื™ื ืžื•ื‘ื ื” ื›ื“ื™ ืœื–ื”ื•ืช ื•ืœืžื ื•ืข ืื•ืชื. ื‘ืžืงื•ื ืœื”ืกืชืžืš ืขืœ ืืžืฆืขื™ ื”ืคื—ืชื” ืฉืœ ืชื•ื›ื ื”, ื”ื˜ื›ื ื•ืœื•ื’ื™ื” ืฉืœื ื• ืžื‘ืฆืขืช ื ื™ืชื•ื— ืžืขืžื™ืง ื‘ืจืžืช ื”ืงื•ื‘ืฅ ืฉืœ ืงื‘ืฆื™ PDF ื›ื“ื™ ืœื”ื‘ื™ืŸ ืืช ื”ืชื ื”ื’ื•ืชื ื•ืืช ื™ื›ื•ืœื•ืช ื”ืžืขืจื›ืช ืฉื”ื ืžื ืกื™ื ืœื ืฆืœ: ื˜ื•ืคืก XFA ืžื•ื˜ืžืข ื”ืžืคื ื” ืœื™ืฉื•ืช ื—ื™ืฆื•ื ื™ืช XML ืžืกื•ื›ื ืช.

ื–ื” ืžืืคืฉืจ ื–ื™ื”ื•ื™ ืื ื•ืžืœื™ื•ืช ืžื‘ื ื™ื•ืช ื”ืžื“ื•ืจื’ื•ืช ืขืœ ื™ื“ื™ ื”ืฉืคืขื” ืืžื™ืชื™ืช ืฉืœ ืžืชืงืคื”, ื˜ื›ื ื™ืงื•ืช ื ื™ืฆื•ืœ ื™ื“ื•ืขื•ืช ื•ืืคื™ืœื• ืžืชืงืคื•ืช ืืคืก-ื™ื•ื ื”ืžืกืชืžื›ื•ืช ืขืœ ืคื’ืžื™ ืื‘ื˜ื—ื” ืœื ืžืชื•ืขื“ื™ื ืื• ืžืชืขื•ืจืจื™ื. ืœืžื™ื“ืข ื ื•ืกืฃ ืขืœ ื–ื™ื”ื•ื™ ืืคืก-ื™ื•ื OPSWAT

3. Secure Software Supply Chain

ืชื”ืœื™ืš ืฉืจืฉืจืช ืืกืคืงื” โ€‹โ€‹ืžืื•ื‘ื˜ื—ืช ืฉืœ ืชื•ื›ื ื” ื™ื›ื•ืœ ืœืกื™ื™ืข ื‘ื–ื™ื”ื•ื™ ื”ืื ืฉื™ืจื•ืช ืื• ืจื›ื™ื‘ ื›ืœืฉื”ื ืžืกืชืžื›ื™ื ืขืœ ื’ืจืกืช Apache Tika ืคื’ื™ืขื” ื”ืžื•ืฉืคืขืช ืž-CVE-2025-66516.

ืขืœ ื™ื“ื™ ืฉื™ืœื•ื‘ ื›ืœื™ ืกืจื™ืงืช ืชืœื•ื™ื•ืช ืื•ื˜ื•ืžื˜ื™ื™ื ื›ืžื• SCA (ื ื™ืชื•ื— ื”ืจื›ื‘ ืชื•ื›ื ื”) ื‘ืฆื™ื ื•ืจื•ืช CI/CD, ืืจื’ื•ื ื™ื ื™ื›ื•ืœื™ื ืœื–ื”ื•ืช ื‘ืื•ืคืŸ ืจืฆื™ืฃ ืกืคืจื™ื•ืช ืžื™ื•ืฉื ื•ืช, ืชืœื•ื™ื•ืช ื˜ืจื ื–ื™ื˜ื™ื‘ื™ื•ืช ืื• ืžื•ื“ื•ืœื™ื ื ืกืชืจื™ื ืฉืขื“ื™ื™ืŸ ืžืชื™ื™ื—ืกื™ื ืœ-Tika โ‰ค 3.2.1. ืœืžื™ื“ืข ื ื•ืกืฃ ืขืœ Supply Chain Software OPSWAT MetaDefender

ืกื•ืจืงื™ื ืืœื” ืžืกืžื ื™ื ืืช ื”ื’ืจืกืื•ืช ื”ืคื’ื™ืขื•ืช ืžื•ืงื“ื, ื•ืžืืคืฉืจื™ื ืœืฆื•ื•ืชื™ื ืœื—ืกื•ื ืคืจื™ืกื•ืช ืื• ืœื”ืคืขื™ืœ ืฉื“ืจื•ื’ื™ื ื—ื•ื‘ื” ืœื’ืจืกืื•ืช ืžืชื•ืงื ื•ืช ื›ืžื• Tika 3.2.2.

ื‘ืฉื™ืœื•ื‘ ืขื ื™ืฆื™ืจืช SBOM (ืจืฉื™ืžื•ืช ื—ื•ืžืจื™ื ืฉืœ ืชื•ื›ื ื”) ื•ื‘ื™ืงื•ืจื•ืช ืžืœืื™ ืชืงื•ืคืชื™ื•ืช, ื’ื™ืฉื” ื–ื• ืžื‘ื˜ื™ื—ื” ื ืจืื•ืช ืžืœืื” ืœืกืคืจื™ื•ืช ืฉืœ ืฆื“ ืฉืœื™ืฉื™ ื•ืžืคื—ื™ืชื” ืืช ื”ืกื™ื›ื•ืŸ ืœื›ื ื™ืกืช ืงื•ื“ ืคื’ื™ืข ืœืชื”ืœื™ืš ื”ื™ื™ืฆื•ืจ.

ืคืจื•ื™ืงื˜ ื”ืžืฉืชืžืฉ ื‘-Apache Tika 2.9.0 ืกื•ืžืŸ ืขืœ ื™ื“ื™ MetaDefender Software Supply Chain

ืœืžื” ืื‘ื˜ื—ื” ืจื‘-ืฉื›ื‘ืชื™ืช ื—ืฉื•ื‘ื”

CVE-2025-66516 ืžื“ื’ื™ื ื›ื™ืฆื“ ื”ืชืงืคื•ืช ืžื•ื“ืจื ื™ื•ืช ื›ืžืขื˜ ื•ืœื ืžืกืชืžื›ื•ืช ืขืœ ื ืงื•ื“ืช ื›ืฉืœ ืื—ืช. ื‘ืžืงื•ื ื–ืืช, ื”ืŸ ืžื ืฆืœื•ืช ืคื•ืจืžื˜ื™ื ืฉืœ ืงื‘ืฆื™ื ืžื”ื™ืžื ื™ื, ืกืคืจื™ื•ืช ื ื™ืชื•ื— ืžื”ื™ืžื ื•ืช ื•ื–ืจื™ืžื•ืช ืขื‘ื•ื“ื” ืื•ื˜ื•ืžืฆื™ื” ืžื”ื™ืžื ื•ืช. ื›ืืฉืจ ืื—ืช ืžื”ื”ื ื—ื•ืช ื”ืœืœื• ื ืฉื‘ืจืช, ืžืขืจื›ื•ืช ื‘ืžื•ืจื“ ื”ื–ืจื ื™ื•ืจืฉื•ืช ืืช ื”ืกื™ื›ื•ืŸ. ื–ื• ื”ืกื™ื‘ื” ืฉื”ืกืชืžื›ื•ืช ืืš ื•ืจืง ืขืœ ืชื™ืงื•ื ื™ื ืื• ื”ื’ื ื•ืช ื”ื™ืงืคื™ื•ืช ื›ื‘ืจ ืื™ื ื” ืžืกืคื™ืงื”.

ืžื•ื“ืœ ืื‘ื˜ื—ื” ืจื‘-ืฉื›ื‘ืชื™ (ื”ืžื›ื•ื ื” ืœืขืชื™ื ืงืจื•ื‘ื•ืช ื”ื’ื ื” ืžืขืžื™ืงื”) ืžื ื™ื— ืฉื‘ืงืจื•ืช ื™ื™ื›ืฉืœื• ื‘ืกื•ืคื• ืฉืœ ื“ื‘ืจ ื•ืžืชื›ื ืŸ ื”ื’ื ื•ืช ื‘ื”ืชืื:

  • ืื ื”ืชื™ืงื•ืŸ ืžืชืขื›ื‘ ืื• ืœื ืฉืœื, ื ื™ืงื•ื™ ืงื‘ืฆื™ ื”ืงืœื˜ ืžื‘ื˜ื™ื— ืฉืชื•ื›ืŸ ืžืกื•ื›ืŸ, ื›ื’ื•ืŸ ื˜ืคืกื™ XFA ืื• ื”ืคื ื™ื•ืช ืœื™ืฉื•ื™ื•ืช ื—ื™ืฆื•ื ื™ื•ืช, ื™ื•ืกืจ ืœืคื ื™ ืฉื”ื•ื ื™ื›ื•ืœ ืœื”ื’ื™ืข ืœืงื•ื“ ืคื’ื™ืข.
  • ืื ืงื•ื‘ืฅ ื–ื“ื•ื ื™ ืขื•ืงืฃ ื‘ื“ื™ืงื•ืช ืกื˜ื˜ื™ื•ืช, ื ื™ืชื•ื— ื”ืชื ื”ื’ื•ืชื™ ื•ืืžื•ืœืฆื™ื” ืขื“ื™ื™ืŸ ื™ื›ื•ืœื™ื ืœื–ื”ื•ืช ื ื™ืกื™ื•ื ื•ืช ื ื™ืฆื•ืœ ืœืจืขื” ืขืœ ืกืžืš ื”ืชื ื”ื’ื•ืช ื‘ื™ืฆื•ืข ืืžื™ืชื™ืช ื•ืœื ื—ืชื™ืžื•ืช ื™ื“ื•ืขื•ืช.
  • ืื ืงื•ื“ ืœื ื‘ื˜ื•ื— ื ื›ื ืก ืœืกื‘ื™ื‘ื” ื“ืจืš ืชืœื•ื™ื•ืช, ื ื”ืœื™ื ืžืื•ื‘ื˜ื—ื™ื ืฉืœ ืฉืจืฉืจืช ืืกืคืงื” โ€‹โ€‹ืฉืœ ืชื•ื›ื ื” ืžืกืคืงื™ื ื ืจืื•ืช ื•ืื›ื™ืคื” ื›ื“ื™ ืœืžื ื•ืข ืคืจื™ืกื” ืฉืœ ืจื›ื™ื‘ื™ื ืคื’ื™ืขื™ื ืžืœื›ืชื—ื™ืœื”.

ื›ืœ ืื—ืช ืžื”ืฉื›ื‘ื•ืช ื”ืœืœื• ืžื˜ืคืœืช ื‘ืฉืœื‘ ืฉื•ื ื” ื‘ืžื—ื–ื•ืจ ื—ื™ื™ ื”ื”ืชืงืคื”: ืœืคื ื™ ื”ื ื™ืชื•ื—, ื‘ืžื”ืœืš ื”ื‘ื™ืฆื•ืข, ื•ืœืื•ืจืš ืชื”ืœื™ืš ื”ืคื™ืชื•ื— ื•ื”ืคืจื™ืกื”. ื™ื—ื“, ื”ืŸ ืžืคื—ื™ืชื•ืช ื”ืŸ ืืช ื”ืกื‘ื™ืจื•ืช ืœื ื™ืฆื•ืœ ื•ื”ืŸ ืืช ืจื“ื™ื•ืก ื”ืคื™ืฆื•ืฅ ืื ืžืชื’ืœื” ืคื’ื™ืขื•ืช ืœืื—ืจ ืฉื”ืžืขืจื›ื•ืช ื›ื‘ืจ ื ืžืฆืื•ืช ื‘ื™ื™ืฆื•ืจ.

ืขื‘ื•ืจ ืืจื’ื•ื ื™ื ื”ืžืขื‘ื“ื™ื ืงื‘ืฆื™ื ืœื ืžื”ื™ืžื ื™ื ื‘ืงื ื” ืžื™ื“ื” ื’ื“ื•ืœ, ื‘ืžื™ื•ื—ื“ ื‘ืฉื™ืจื•ืชื™ backend ืื•ื˜ื•ืžื˜ื™ื™ื, ื’ื™ืฉื” ืจื‘-ืฉื›ื‘ืชื™ืช ื–ื• ื—ื™ื•ื ื™ืช. ืคื’ื™ืขื•ื™ื•ืช ื›ืžื• CVE-2025-66516 ื™ืžืฉื™ื›ื• ืœืฆื•ืฅ, ืืš ืขื ืื‘ื˜ื—ื” ืจื‘-ืฉื›ื‘ืชื™ืช ื‘ืžืงื•ื, ื”ืŸ ื”ื•ืคื›ื•ืช ืœืกื™ื›ื•ื ื™ื ื ื™ืชื ื™ื ืœื ื™ื”ื•ืœ ื•ืœื ืœื›ืฉืœื™ื ืงืจื™ื˜ื™ื™ื.

ืื•ื“ื•ืช ืืคืืฆ'ื™ ื˜ื™ืงื”

Apache Tika ื”ื™ื ืกืคืจื™ื™ืช Java ืฉืžืงื‘ืœืช ืกื•ื’ื™ื ืจื‘ื™ื ืฉืœ ืงื‘ืฆื™ื (PDF, Word, PowerPoint ื•ื›ื•') ื•ืžื—ืœืฆืช ื˜ืงืกื˜ ื•ืžื˜ื-ื“ืื˜ื” ื›ื“ื™ ืฉืืคืœื™ืงืฆื™ื•ืช ื™ื•ื›ืœื• ืœืื ื“ืงืก, ืœื—ืคืฉ ืื• ืœื ืชื— ืžืกืžื›ื™ื. ื”ื™ื ื ืžืฆืืช ื‘ืฉื™ืžื•ืฉ ื ืจื—ื‘ ื‘ืžืขืจื›ื•ืช ื›ืžื• ืžื ื•ืขื™ ื—ื™ืคื•ืฉ, ื›ืœื™ ื’ื™ืœื•ื™ ืืœืงื˜ืจื•ื ื™ ื•ื›ืœ ืืคืœื™ืงืฆื™ื™ืช ืื™ื ื˜ืจื ื˜ ื”ืžืืคืฉืจืช ืœืžืฉืชืžืฉื™ื ืœื”ืขืœื•ืช ืžืกืžื›ื™ื ืœืขื™ื‘ื•ื“ ืื•ื˜ื•ืžื˜ื™.

ืื•ื“ื•ืช CVE-2025-66516

ืžืฉื˜ื— ื”ื”ืชืงืคื” ื”ื•ื ืคื’ื™ืขื•ืช ืžืกื•ื’ XXE (ื™ืฉื•ืช ื—ื™ืฆื•ื ื™ืช XML) ื”ืžื•ืคืขืœืช ื›ืืฉืจ Tika ืžื ืชื—ืช ืงื‘ืฆื™ PDF ื”ืžื›ื™ืœื™ื ื˜ื•ืคืก XFA (ืืจื›ื™ื˜ืงื˜ื•ืจืช ื˜ืคืกื™ XML) ื–ื“ื•ื ื™. XXE ืคื™ืจื•ืฉื• ืฉื›ืืฉืจ Tika ืžืขื‘ื“ืช XML ื‘ืชื•ืš ื”-PDF, ื ื™ืชืŸ ืœื”ืขืจื™ื ืขืœื™ื” ื•ืœื˜ืขื•ืŸ "ื™ืฉื•ื™ื•ืช ื—ื™ืฆื•ื ื™ื•ืช" ื”ืžืฆื‘ื™ืขื•ืช ืขืœ ืงื‘ืฆื™ื ืžืงื•ืžื™ื™ื ืื• ื›ืชื•ื‘ื•ืช URL ืžืจื•ื—ืงื•ืช, ื“ื‘ืจ ืฉืœื ืืžื•ืจ ืœืงืจื•ืช.

CVE-2025-66516 ื”ื™ื ืคืจืฆืช ืื‘ื˜ื—ื” ืงืจื™ื˜ื™ืช ื‘-Apache Tika ื”ืžืืคืฉืจืช ืœืชื•ืงืฃ ืœื”ืคืขื™ืœ ื”ื–ืจืงืช XXE ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ืงื•ื‘ืฅ PDF ืฉื ื•ืฆืจ ื‘ืžื™ื•ื—ื“ ืขื ื˜ื•ืคืก XFA ื–ื“ื•ื ื™. ื”ืคื’ื™ืขื•ืช ืžืฉืคื™ืขื” ืขืœ ืžื•ื“ื•ืœื™ื ืžืจื•ื‘ื™ื (ื’ืจืกืื•ืช tika-core โ‰ค 3.2.1, tika-pdf-module ื•-tika-parsers) ื•ื ื•ืฉืืช ืืช ื“ื™ืจื•ื’ ื”ื—ื•ืžืจื” ืฉืœ CVSS 9.8. ืื ื”ื™ื ื™ื ื•ืฆืœื”, ื”ืชื•ืงืคื™ื ืขืœื•ืœื™ื ืœืงืจื•ื ืงื‘ืฆื™ ืฉืจืช ืจื’ื™ืฉื™ื, ืœื‘ืฆืข ื–ื™ื•ืฃ ื‘ืงืฉื•ืช ื‘ืฆื“ ื”ืฉืจืช (SSRF) ืื• ืืคื™ืœื• ืœื”ืฉื™ื’ ื‘ื™ืฆื•ืข ืงื•ื“ ืžืจื—ื•ืง.

ื‘ืžืงืจื” ื–ื”, ื”ืคื’ื™ืขื•ืช ื ืžืฆืืช ื‘ืกืคืจื™ื™ืช ื”ืœื™ื‘ื” ืฉืœ ื˜ื™ืงื” (tika-core), ืœื ืจืง ื‘ืžื•ื“ื•ืœ ืžื ืชื— ื”-PDF, ื›ืš ืฉืืคื™ืœื• ืขื“ื›ื•ืŸ ืฉืœ ืžื•ื“ื•ืœ ื”-PDF ื‘ืœื‘ื“ ืื™ื ื• ืžืกืคื™ืง.

ืžืงืจื™ ืฉื™ืžื•ืฉ ืื•ืคื™ื™ื ื™ื™ื ื‘ืกื™ื›ื•ืŸ

ื›ืœ ื™ื™ืฉื•ื ื”ืžืืคืฉืจ ืœืžืฉืชืžืฉื™ื ืœื”ืขืœื•ืช ืงื‘ืฆื™ PDF ืœืฆื•ืจืš ืชืฆื•ื’ื” ืžืงื“ื™ืžื”, ืื™ื ื“ื•ืงืก ืื• ื—ื™ืœื•ืฅ ื˜ืงืกื˜, ืื• ื”ืžืฉืชืžืฉ ื‘-Tika ื‘ืจืงืข ื›ื“ื™ ืœืขื‘ื“ ืืช ื”ื”ืขืœืื•ืช ื”ืœืœื• ื‘ืื•ืคืŸ ืื•ื˜ื•ืžื˜ื™, ื ืžืฆื ื‘ืกื™ื›ื•ืŸ, ื‘ืžื™ื•ื—ื“ ืื ื”ื•ื ืคื•ืขืœ ื‘ืฉื™ืจื•ืช backend ืฉื™ืฉ ืœื• ื’ื™ืฉื” ืœืจืฉืชื•ืช ืคื ื™ืžื™ื•ืช ืื• ืงื‘ืฆื™ื ืจื’ื™ืฉื™ื.

ื”ื’ืŸ ืขืœ ืชื”ืœื™ื›ื™ ื”ืขื‘ื•ื“ื” ืฉืœ ื”ืงื‘ืฆื™ื ืฉืœืš

ืœืžื“ ื›ื™ืฆื“ OPSWAT ื˜ื›ื ื•ืœื•ื’ื™ื•ืช ื™ื›ื•ืœื•ืช ืœืขื‘ื•ื“ ื™ื—ื“ ื›ื“ื™ ืœื”ื’ืŸ ืขืœ ื”ืืจื’ื•ืŸ ืฉืœืš ืžืคื ื™ ืคื’ื™ืขื•ื™ื•ืช ื™ื“ื•ืขื•ืช ื•ื’ื ืžืคื ื™ ืื™ื•ืžื™ ื™ื•ื ืืคืก ืžืชืคืชื—ื™ื.

ื”ื™ืฉืืจ ืžืขื•ื“ื›ืŸ ืขื OPSWAT !

ื”ื™ืจืฉืžื• ืขื•ื“ ื”ื™ื•ื ื›ื“ื™ ืœืงื‘ืœ ืืช ื”ืขื“ื›ื•ื ื™ื ื”ืื—ืจื•ื ื™ื ืฉืœ ื”ื—ื‘ืจื”, ืกื™ืคื•ืจื™ื, ืžื™ื“ืข ืขืœ ืื™ืจื•ืขื™ื ื•ืขื•ื“.