ZeroHour

CVE-2022-24682

KEV ransomware PoC large1

Cross-Site Scripting in Synacor Zimbra Collaboration Suite Calendar

CISA: Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability

CVSS 3.1
6.1 medium
EPSS
31%p98
Published
()
KEV added
AI analysis

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (CWE-79) flaw with improper encoding/escaping (CWE-116) in its Calendar feature, allowing an attacker to execute arbitrary code. The flaw is triggered through the Calendar functionality, where attacker-supplied content is rendered without proper encoding, enabling script/code execution in the context of affected ZCS deployments. A successful attacker can execute arbitrary code in the targeted environment, and CISA notes known ransomware use in the wild. Organizations running Synacor ZCS are affected; the specific affected version ranges are not stated in the available data. The vulnerability was added to the CISA Known Exploited Vulnerabilities catalog on 2022-02-25 with a 30.9% EPSS probability of exploitation within 30 days, though no public proof-of-concept is known.

What to do: Apply updates per vendor instructions, as required by the CISA KEV listing. Because ransomware use is known, prioritize patching internet-facing ZCS servers, review Zimbra mailbox/Calendar logs for signs of malicious items or unauthorized access, and confirm users' sessions and accounts have not been compromised. Until patched, treat untrusted calendar invites as untrusted input and limit exposure of the ZCS web interface.

Affected
Synacor Zimbra Collaboration Suite (ZCS) - Calendar feature
Estimated exposure
largetens of thousands of internet-exposed Zimbra servers (public scans have shown roughly 50,000+ ZCS instances online) — Public internet-wide scans have repeatedly counted on the order of tens of thousands of Zimbra ZCS servers exposed to the internet, and ZCS's broad enterprise/hosted email installed base makes exposure plausibly in that range.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document.

CISA Known Exploited Vulnerability
Affected
Synacor Zimbra Collaborate Suite (ZCS)
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
synacor
Products
zimbra collaboration suite
Weakness
CWE-116
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news