CWE-78: Vô hiệu hóa không đúng các phần tử đặc biệt được sử dụng trong lệnh hệ điều hành ('Chèn lệnh hệ điều hành')

CWE-78 là gì?

Sản phẩm xây dựng lệnh hệ điều hành từ dữ liệu chịu ảnh hưởng bên ngoài nhưng không vô hiệu hóa đúng các phần tử đặc biệt có thể thay đổi lệnh dự kiến trước khi lệnh được thực thi.

Thống kê dữ liệu

THỨ HẠNG OWASP TOP 10:20255 — A05:2025 — Injection
TỔNG SỐ CVE LIÊN QUAN (365 NGÀY)1.045
MỨC TRỪU TƯỢNGCơ bản
KHẢ NĂNG KHAI THÁCCao

Số lượng lỗ hổng nằm trong CWE-78

1.045 lỗ hổngTăng 333,6% so với cùng kỳ

Số lượng lỗ hổng trong CISA KEV của CWE-78

11 lỗ hổngTăng 83,3% so với cùng kỳ

Định nghĩa chính thức

TheoMitre CWE

Chi tiết kỹ thuật

Điểm yếu này có thể ảnh hưởng đến các ứng dụng thực thi lệnh hệ điều hành thay mặt người dùng, bao gồm ứng dụng web nơi kẻ tấn công không có quyền truy cập trực tiếp vào hệ điều hành. Nó thường xuất hiện dưới hai dạng: dữ liệu không tin cậy vốn chỉ được dùng làm đối số cho một chương trình cố định nhưng chứa dấu phân cách lệnh hoặc siêu ký tự để chạy thêm chương trình, hoặc dữ liệu không tin cậy quyết định toàn bộ lệnh và chương trình được thực thi, từ đó cho phép chạy lệnh tùy ý. Tác động có thể nghiêm trọng hơn khi tiến trình bị ảnh hưởng có đặc quyền cao hoặc không tuân thủ nguyên tắc đặc quyền tối thiểu, vì lệnh do kẻ tấn công kiểm soát có thể chạy với quyền mà kẻ tấn công không trực tiếp có.

Đặc điểm

Đây là điểm yếu cơ sở, cấu trúc đơn giản, phát sinh trong giai đoạn triển khai. Điểm cốt lõi là trộn cú pháp điều khiển với dữ liệu chịu ảnh hưởng bên ngoài trong lệnh hệ điều hành, dù dữ liệu chỉ được đưa vào đối số của một chương trình cố định hay quyết định cả chương trình và lệnh cần chạy. Các thuật ngữ liên quan gồm shell injection, shell metacharacters và OS command injection; điểm yếu này phân biệt với nhưng có thể đi kèm argument injection.

Hậu quả thường gặp

Kẻ tấn công có thể thực thi lệnh hệ điều hành trái phép, vô hiệu hóa hoặc làm ứng dụng gặp sự cố, cũng như đọc hay sửa tệp, thư mục và dữ liệu ứng dụng vượt quá quyền dự kiến. Hoạt động độc hại có thể trông như bắt nguồn từ ứng dụng hoặc chủ sở hữu ứng dụng, ảnh hưởng đến tính bí mật, toàn vẹn, sẵn sàng và khả năng chống chối bỏ, đồng thời có thể giúp che giấu hoạt động.

Dữ liệu MITRE CWE chính thức
Tác độngPhạm viDiễn giải
Thực thi mã hoặc lệnh trái phép, Từ chối dịch vụ: sập, thoát hoặc khởi động lại, Đọc tệp hoặc thư mục, Thay đổi tệp hoặc thư mục, Đọc dữ liệu ứng dụng, Thay đổi dữ liệu ứng dụng, Che giấu hoạt độngTính bí mật, Tính toàn vẹn, Tính sẵn sàng, Chống chối bỏAttackers could execute unauthorized operating system commands, which could then be used to disable the product, or read and modify data for which the attacker does not have permissions to access directly. Since the targeted application is directly executing the commands instead of the attacker, any malicious activities may appear to come from the application or the application's owner.

Biện pháp giảm thiểu rủi ro

Kiến trúc và thiết kế: Ưu tiên lời gọi thư viện thay vì tiến trình bên ngoài, đồng thời giữ dữ liệu dùng để tạo lệnh ngoài quyền kiểm soát bên ngoài nếu có thể, và ánh xạ các giá trị đầu vào cố định như mã số sang tên tệp hoặc URL đã biết. Lặp lại các kiểm tra bảo mật phía máy khách ở máy chủ, và dùng thư viện hoặc framework đã được thẩm định để tách dữ liệu khỏi mã. Khi có thể, dùng cơ chế tham số hóa có cấu trúc với từng đối số riêng thay cho một chuỗi lệnh gọi shell, chẳng hạn giao diện nhận mảng đối số thay vì cách gọi kiểu system.

Triển khai: Đặt dấu ngoặc và escape đúng cho đối số; khi khả thi, dùng allowlist cực kỳ nghiêm ngặt, rồi đặt từng đối số trong dấu ngoặc sau bước lọc hoặc escape. Nếu chương trình hỗ trợ, ưu tiên truyền đối số qua tệp đầu vào hoặc đầu vào chuẩn. Áp dụng chiến lược xác thực “chấp nhận giá trị hợp lệ đã biết”, dựa trên kiểu, độ dài, cú pháp, giá trị được phép và quy tắc nghiệp vụ; tuy nhiên, xác thực chỉ là lớp phòng thủ bổ sung, không thay thế encoding, escape và quoting. Giữ thông báo lỗi ở mức tối thiểu cần thiết và ghi chi tiết cần thiết vào nhật ký được bảo vệ phù hợp.

Vận hành và gia cố: Dùng sandbox hoặc jail, allowlist lệnh ở thời gian chạy và quyền thấp nhất cần thiết, đồng thời hiểu rằng các biện pháp này thường chỉ giới hạn tác động chứ không loại bỏ điểm yếu. Cơ chế lan truyền taint tự động có thể ngăn thực thi lệnh với biến bị taint, nhưng phải xác thực đúng để loại bỏ trạng thái taint. Application firewall có thể cung cấp bảo vệ tạm thời hoặc phòng thủ nhiều lớp, nhưng có thể bỏ sót vectơ đầu vào, bị vượt qua hoặc từ chối yêu cầu hợp lệ. Khi phù hợp, không sử dụng PHP register_globals và không tái tạo tính năng này một cách không an toàn. Tránh các điểm yếu liên quan đến thiết kế jail, bao gồm CWE-243.

Dữ liệu MITRE CWE chính thức
  1. Kiến trúc và thiết kếIf at all possible, use library calls rather than external processes to recreate the desired functionality.
  2. Môi trường cô lập (sandbox/jail) · Kiến trúc và thiết kế, Vận hành · Hiệu quả: Hạn chếRun the code in a "jail" or similar sandbox environment that enforces strict boundaries between the process and the operating system. This may effectively restrict which files can be accessed in a particular directory or which commands can be executed by the software. OS-level examples include the Unix chroot jail, AppArmor, and SELinux. In general, managed code may provide some protection. For example, java.io.FilePermission in the Java SecurityManager allows the software to specify restrictions on file operations. This may not be a feasible solution, and it only limits the impact to the operating system; the rest of the application may still be subject to compromise. Be careful to avoid CWE-243 and other weaknesses related to jails.The effectiveness of this mitigation depends on the prevention capabilities of the specific sandbox or jail being used and might only help to reduce the scope of an attack, such as restricting the attacker to certain system calls or limiting the portion of the file system that can be accessed.
  3. Giảm bề mặt tấn công · Kiến trúc và thiết kếFor any data that will be used to generate a command to be executed, keep as much of that data out of external control as possible. For example, in web applications, this may require storing the data locally in the session's state instead of sending it out to the client in a hidden form field.
  4. Kiến trúc và thiết kếFor any security checks that are performed on the client side, ensure that these checks are duplicated on the server side, in order to avoid CWE-602. Attackers can bypass the client-side checks by modifying values after the checks have been performed, or by changing the client to remove the client-side checks entirely. Then, these modified values would be submitted to the server.
  5. Thư viện hoặc framework · Kiến trúc và thiết kếUse a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid. For example, consider using the ESAPI Encoding control [REF-45] or a similar tool, library, or framework. These will help the programmer encode outputs in a manner less prone to error.
  6. Mã hóa ký tự đầu ra · Hiện thực hóaWhile it is risky to use dynamically-generated query strings, code, or commands that mix control and data together, sometimes it may be unavoidable. Properly quote arguments and escape any special characters within those arguments. The most conservative approach is to escape or filter all characters that do not pass an extremely strict allowlist (such as everything that is not alphanumeric or white space). If some special characters are still needed, such as white space, wrap each argument in quotes after the escaping/filtering step. Be careful of argument injection (CWE-88).
  7. Hiện thực hóaIf the program to be executed allows arguments to be specified within an input file or from standard input, then consider using that mode to pass arguments instead of the command line.
  8. Tham số hóa · Kiến trúc và thiết kếIf available, use structured mechanisms that automatically enforce the separation between data and code. These mechanisms may be able to provide the relevant quoting, encoding, and validation automatically, instead of relying on the developer to provide this capability at every point where output is generated. Some languages offer multiple functions that can be used to invoke commands. Where possible, identify any function that invokes a command shell using a single string, and replace it with a function that requires individual arguments. These functions typically perform appropriate quoting and filtering of arguments. For example, in C, the system() function accepts a string that contains the entire command to be executed, whereas execl(), execve(), and others require an array of strings, one for each argument. In Windows, CreateProcess() only accepts one command at a time. In Perl, if system() is provided with an array of arguments, then it will quote each of the arguments.
  9. Kiểm tra dữ liệu đầu vào · Hiện thực hóaAssume all input is malicious. Use an "accept known good" input validation strategy, i.e., use a list of acceptable inputs that strictly conform to specifications. Reject any input that does not strictly conform to specifications, or transform it into something that does. When performing input validation, consider all potentially relevant properties, including length, type of input, the full range of acceptable values, missing or extra inputs, syntax, consistency across related fields, and conformance to business rules. As an example of business rule logic, "boat" may be syntactically valid because it only contains alphanumeric characters, but it is not valid if the input is only expected to contain colors such as "red" or "blue." Do not rely exclusively on looking for malicious or malformed inputs. This is likely to miss at least one undesirable input, especially if the code's environment changes. This can give attackers enough room to bypass the intended validation. However, denylists can be useful for detecting potential attacks or determining which inputs are so malformed that they should be rejected outright. When constructing OS command strings, use stringent allowlists that limit the character set based on the expected value of the parameter in the request. This will indirectly limit the scope of an attack, but this technique is less important than proper output encoding and escaping. Note that proper output encoding, escaping, and quoting is the most effective solution for preventing OS command injection, although input validation may provide some defense-in-depth. This is because it effectively limits what will appear in output. Input validation will not always prevent OS command injection, especially if you are required to support free-form text fields that could contain arbitrary characters. For example, when invoking a mail program, you might need to allow the subject field to contain otherwise-dangerous inputs like ";" and ">" characters, which would need to be escaped or otherwise handled. In this case, stripping the character might reduce the risk of OS command injection, but it would produce incorrect behavior because the subject field would not be recorded as the user intended. This might seem to be a minor inconvenience, but it could be more important when the program relies on well-structured subject lines in order to pass messages to other components. Even if you make a mistake in your validation (such as forgetting one out of 100 input fields), appropriate encoding is still likely to protect you from injection-based attacks. As long as it is not done in isolation, input validation is still a useful technique, since it may significantly reduce your attack surface, allow you to detect some attacks, and provide other security benefits that proper encoding does not address.
  10. Áp đặt quy tắc bằng chuyển đổi · Kiến trúc và thiết kếWhen the set of acceptable objects, such as filenames or URLs, is limited or known, create a mapping from a set of fixed input values (such as numeric IDs) to the actual filenames or URLs, and reject all other inputs.
  11. Gia cố quá trình biên dịch hoặc xây dựng · Vận hànhRun the code in an environment that performs automatic taint propagation and prevents any command execution that uses tainted variables, such as Perl's "-T" switch. This will force the program to perform validation steps that remove the taint, although you must be careful to correctly validate your inputs so that you do not accidentally mark dangerous inputs as untainted (see CWE-183 and CWE-184).
  12. Gia cố môi trường · Vận hànhRun the code in an environment that performs automatic taint propagation and prevents any command execution that uses tainted variables, such as Perl's "-T" switch. This will force the program to perform validation steps that remove the taint, although you must be careful to correctly validate your inputs so that you do not accidentally mark dangerous inputs as untainted (see CWE-183 and CWE-184).
  13. Hiện thực hóaEnsure that error messages only contain minimal details that are useful to the intended audience and no one else. The messages need to strike the balance between being too cryptic (which can confuse users) or being too detailed (which may reveal more than intended). The messages should not reveal the methods that were used to determine the error. Attackers can use detailed information to refine or optimize their original attack, thereby increasing their chances of success. If errors must be captured in some detail, record them in log messages, but consider what could occur if the log messages can be viewed by attackers. Highly sensitive information such as passwords should never be saved to log files. Avoid inconsistent messaging that might accidentally tip off an attacker about internal state, such as whether a user account exists or not. In the context of OS Command Injection, error information passed back to the user might reveal whether an OS command is being executed and possibly which command is being used.
  14. Môi trường cô lập (sandbox/jail) · Vận hànhUse runtime policy enforcement to create an allowlist of allowable commands, then prevent use of any command that does not appear in the allowlist. Technologies such as AppArmor are available to do this.
  15. Tường lửa · Vận hành · Hiệu quả: KháUse an application firewall that can detect attacks against this weakness. It can be beneficial in cases in which the code cannot be fixed (because it is controlled by a third party), as an emergency prevention measure while more comprehensive software assurance measures are applied, or to provide defense in depth [REF-1481].An application firewall might not cover all possible input vectors. In addition, attack techniques might be available to bypass the protection mechanism, such as using malformed inputs that can still be processed by the component that receives those inputs. Depending on functionality, an application firewall might inadvertently reject or modify legitimate requests. Finally, some manual effort may be required for customization.
  16. Gia cố môi trường · Kiến trúc và thiết kế, Vận hànhRun your code using the lowest privileges that are required to accomplish the necessary tasks [REF-76]. If possible, create isolated accounts with limited privileges that are only used for a single task. That way, a successful attack will not immediately give the attacker access to the rest of the software or its environment. For example, database applications rarely need to run as the database administrator, especially in day-to-day operations.
  17. Gia cố môi trường · Vận hành, Hiện thực hóaWhen using PHP, configure the application so that it does not use register_globals. During implementation, develop the application so that it does not rely on this feature, but be wary of implementing a register_globals emulation that is subject to weaknesses such as CWE-95, CWE-621, and similar issues.

Cách phát hiện trong hệ thống

Có thể kết hợp các phương pháp thủ công và tự động. Rà soát mã nguồn thủ công, kiểm tra điểm tập trung, rà soát kiến trúc hoặc thiết kế và phương pháp hình thức có thể đạt mức bao phủ cao hoặc hiệu quả cao khi đánh giá được toàn bộ đường dẫn thực thi lệnh. Phân tích tĩnh tự động trên mã nguồn, nhị phân hoặc bytecode có thể phát hiện luồng dữ liệu đi vào thao tác thực thi lệnh, nhưng có thể tạo cảnh báo giả khi không nhận diện được bước xác thực, bỏ sót API tùy chỉnh hoặc thư viện bên thứ ba không có mã để phân tích; không thể đạt độ chính xác và bao phủ tuyệt đối.

Kiểm thử động có thể sử dụng fuzzing, kiểm thử độ bền, fault injection, trình quét ứng dụng web, dịch vụ web và cơ sở dữ liệu. Các phương pháp này thường chỉ cung cấp mức bao phủ vừa phải hoặc từng phần và có thể làm chậm hoạt động, nhưng sản phẩm không được trở nên mất ổn định, bị lỗi hoặc tạo kết quả sai trong quá trình kiểm thử.

Dữ liệu MITRE CWE chính thức
Phương phápCách làmHiệu quả
Phân tích tĩnh tự độngThis weakness can often be detected using automated static analysis tools. Many modern tools use data flow analysis or constraint-based techniques to minimize the number of false positives. Automated static analysis might not be able to recognize when proper input validation is being performed, leading to false positives - i.e., warnings that do not have any security consequences or require any code changes. Automated static analysis might not be able to detect the usage of custom API functions or third-party libraries that indirectly invoke OS commands, leading to false negatives - especially if the API/library code is not available for analysis.This is not a perfect solution, since 100% accuracy and coverage are not feasible.—
Phân tích động tự độngThis weakness can be detected using dynamic tools and techniques that interact with the product using large test suites with many diverse inputs, such as fuzz testing (fuzzing), robustness testing, and fault injection. The product's operation may slow down, but it should not become unstable, crash, or generate incorrect results.Khá
Phân tích tĩnh thủ côngSince this weakness does not typically appear frequently within a single software package, manual white box techniques may be able to provide sufficient code coverage and reduction of false positives if all potentially-vulnerable operations can be assessed within limited time constraints.Cao
Phân tích tĩnh tệp nhị phân hoặc bytecode tự độngAccording to SOAR [REF-1479], the following detection techniques may be useful: ``` Highly cost effective: ``` Bytecode Weakness Analysis - including disassembler + source code weakness analysis Binary Weakness Analysis - including disassembler + source code weakness analysisCao
Phân tích động với diễn giải kết quả tự độngAccording to SOAR [REF-1479], the following detection techniques may be useful: ``` Cost effective for partial coverage: ``` Web Application Scanner Web Services Scanner Database ScannersSOAR một phần
Phân tích động với diễn giải kết quả thủ côngAccording to SOAR [REF-1479], the following detection techniques may be useful: ``` Cost effective for partial coverage: ``` Fuzz Tester Framework-based FuzzerSOAR một phần
Phân tích tĩnh mã nguồn thủ côngAccording to SOAR [REF-1479], the following detection techniques may be useful: ``` Highly cost effective: ``` Manual Source Code Review (not inspections) ``` Cost effective for partial coverage: ``` Focused Manual Spotcheck - Focused manual analysis of sourceCao
Phân tích tĩnh mã nguồn tự độngAccording to SOAR [REF-1479], the following detection techniques may be useful: ``` Highly cost effective: ``` Source code Weakness Analyzer Context-configured Source Code Weakness AnalyzerCao
Rà soát kiến trúc hoặc thiết kếAccording to SOAR [REF-1479], the following detection techniques may be useful: ``` Highly cost effective: ``` Formal Methods / Correct-By-Construction ``` Cost effective for partial coverage: ``` Inspection (IEEE 1028 standard) (can apply to requirements, design, source code, etc.)Cao

Lỗ hổng điển hình

Hồ sơ chính thức liệt kê các trường hợp sau là ví dụ đại diện, không phải danh sách đầy đủ: CVE-2024-53899 liên quan đến chuỗi mẫu không được đặt dấu ngoặc và siêu ký tự shell trong tên thư mục; CVE-2025-44844 liên quan đến chức năng tải tệp của điểm truy cập không dây, sử dụng tên tệp lấy từ header Content-Disposition; CVE-2024-6091 và CVE-2024-44335 minh họa các chuỗi lỗi có liên quan đến denylist không đầy đủ cho đường dẫn hoặc ký tự; CVE-2024-41316 liên quan đến os.execute trong ứng dụng Lua trên thiết bị mạng; còn CVE-2024-52803 liên quan đến việc sử dụng không an toàn Popen trong quá trình huấn luyện LLM. Các ví dụ cũ hơn gồm chèn lệnh trong bộ định tuyến Wi-Fi, chức năng quản lý cấu hình mạng và máy chủ web, xử lý tên tệp FTP và liên kết telnet, tên tệp ZIP, biến môi trường, URL HTTPS, cũng như tệp hoặc tham số chứa siêu ký tự shell, gồm CVE-2020-10987, CVE-2020-9054, CVE-1999-0067, CVE-2002-0061, CVE-2003-0041, CVE-2008-2575, CVE-2002-1898, CVE-2008-4304, CVE-2008-4796, CVE-2007-3572 và CVE-2012-1988. CVE-2001-1246 còn cho thấy chèn lệnh hệ điều hành có thể đồng thời tồn tại với chèn đối số.

Dữ liệu MITRE CWE chính thức

Dưới đây là các lỗ hổng tiêu biểu liên quan đến CWE-78, dựa theo mức độ ưu tiên

Nguồn (14)

CWE™ Program, operated by The MITRE Corporation. Copyright © 2006–2026, The MITRE Corporation. The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. CWE Terms of Use.

Tìm hiểu thêm

Kiểm tra chuyên sâu cùng giải pháp quản lý rủi ro Web toàn diện

Giải pháp CyStack VulnScan liên tục phát hiện tài sản, xác minh lỗ hổng và giúp đội ngũ bảo mật ưu tiên khắc phục cho toàn bộ doanh nghiệp.

Khám phá CyStack VulnScan