ZeroHour

CVE-2022-27926

KEVlarge

Reflected XSS in Synacor Zimbra Collaboration Suite 9.0 (launchNewWindow.jsp)

CISA: Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

CVSS 3.1
6.1 medium
EPSS
18%p97
Published
()
KEV added
AI analysis

CVE-2022-27926 is a reflected cross-site scripting (CWE-79) flaw in the /public/launchNewWindow.jsp component of Zimbra Collaboration Suite (ZCS) 9.0. An unauthenticated attacker can craft a request to this page whose parameters are reflected into the rendered page, so arbitrary web script or HTML executes in the victim's browser when the user visits the attacker-supplied link (consistent with the CVSS user-interaction requirement). Successful exploitation lets the attacker run script in the context of the user's webmail session — for example to steal cookies or credentials, issue further requests against the server, or display attacker-controlled content — with limited-to-low confidentiality and integrity impact and no availability impact. Any organization running unpatched ZCS 9.0, particularly self-hosted, internet-exposed webmail servers used by enterprises and government entities, is affected. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2023-04-03, and reporting ties Zimbra exploitation to the Winter Vivern APT's targeting of European government and NATO-country email portals; EPSS assigns a 17.6% probability of exploitation within 30 days.

What to do: Apply the current ZCS 9.0 patch/updates from the vendor per Synacor/Zimbra's instructions, as this is the required action in CISA's KEV catalog, prioritizing internet-exposed webmail servers. Review web logs for requests to /public/launchNewWindow.jsp containing unexpected script or HTML in request parameters, and consider restricting access to /public/ if it is not required. Because exploitation requires user interaction, warn users about suspicious webmail links while patching is completed.

Affected
Synacor Zimbra Collaboration Suite (ZCS)9.0 (per the CVE description; apply current vendor patches)
Estimated exposure
largetens of thousands of internet-exposed Zimbra webmail servers (public internet scans have shown on the order of 50,000–100,000 exposed ZCS instances), of which… — Public internet-wide scans (e.g., Shodan) have consistently shown tens of thousands of exposed Zimbra Collaboration Suite servers, and ZCS 9.0 was among the most widely deployed self-hosted webmail releases when this flaw was exploited.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allows unauthenticated attackers to execute arbitrary web script or HTML via request parameters.

CISA Known Exploited Vulnerability
Affected
Synacor Zimbra Collaboration Suite (ZCS)
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
synacor
Products
zimbra collaboration suite
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news