ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Roundcube webmail zero-day exploited to spy on government entities (CVE-2023-5631)

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-35730
Cross-Site Scripting in Roundcube Webmail Plain-Text Email Link Handling

Roundcube Webmail contains a cross-site scripting (XSS) flaw (CWE-79) in the link-reference handling of rcube_string_replacer.php, where the linkref_addindex function mishandles JavaScript embedded in a link element of a plain-text email. An attacker triggers the flaw simply by sending a crafted plain-text message to a victim; when the message is processed/displayed in the Roundcube interface, the embedded script executes in the context of the victim's webmail session. Successful exploitation can lead to session hijacking, theft of webmail cookies or credentials, and arbitrary actions in the victim's mailbox. Any deployment of Roundcube Webmail is affected, which includes self-hosted instances and webmail offered by hosting providers, ISPs, and universities. Although no public proof-of-concept is known, CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2023-06-22, confirming exploitation in the wild; ransomware association is unknown, and no CVSS score is yet available, though EPSS puts 30-day exploitation probability at 32.7% (98th percentile).

Do: Apply the vendor's updated Roundcube release per CISA's required action (updates per vendor instructions); since no specific fixed versions appear in this data, install the latest patched release of your deployed 1.x branch and verify with the vendor advisory. Check webmail servers for processing of plain-text messages with link-reference elements and review logs for anomalous webmail sessions; treat KEV-listed status as evidence of active exploitation and prioritize internet-exposed Roundcube instances.

6.133% KEV
  • Roundcube Webmail
masslikely >1M users across tens of thousands of exposed instances (Roundcube is bundled as webmail in cPanel/Plesk and by many ISPs)
CVE-2022-27926
Reflected XSS in Synacor Zimbra Collaboration Suite 9.0 (launchNewWindow.jsp)

CVE-2022-27926 is a reflected cross-site scripting (CWE-79) flaw in the /public/launchNewWindow.jsp component of Zimbra Collaboration Suite (ZCS) 9.0. An unauthenticated attacker can craft a request to this page whose parameters are reflected into the rendered page, so arbitrary web script or HTML executes in the victim's browser when the user visits the attacker-supplied link (consistent with the CVSS user-interaction requirement). Successful exploitation lets the attacker run script in the context of the user's webmail session — for example to steal cookies or credentials, issue further requests against the server, or display attacker-controlled content — with limited-to-low confidentiality and integrity impact and no availability impact. Any organization running unpatched ZCS 9.0, particularly self-hosted, internet-exposed webmail servers used by enterprises and government entities, is affected. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2023-04-03, and reporting ties Zimbra exploitation to the Winter Vivern APT's targeting of European government and NATO-country email portals; EPSS assigns a 17.6% probability of exploitation within 30 days.

Do: Apply the current ZCS 9.0 patch/updates from the vendor per Synacor/Zimbra's instructions, as this is the required action in CISA's KEV catalog, prioritizing internet-exposed webmail servers. Review web logs for requests to /public/launchNewWindow.jsp containing unexpected script or HTML in request parameters, and consider restricting access to /public/ if it is not required. Because exploitation requires user interaction, warn users about suspicious webmail links while patching is completed.

6.118% KEV
  • Synacor Zimbra Collaboration Suite (ZCS) 9.0 (per the CVE description; apply current vendor patches)
largetens of thousands of internet-exposed Zimbra webmail servers (public internet scans have shown on the order of 50,000–100,000 exposed ZCS instances), of which…
CVE-2023-5631
Stored XSS in Roundcube Webmail exploited in the wild (CVE-2023-5631)

CVE-2023-5631 is a stored cross-site scripting (XSS) flaw in Roundcube Webmail caused by insufficient sanitization of SVG content embedded in HTML email by program/lib/Roundcube/rcube_washtml.php. A remote attacker triggers it by sending a crafted HTML email containing a malicious SVG document; when the recipient views the message, arbitrary JavaScript is loaded in their browser session. This lets the attacker act as the victim within the webmail session — for example reading mail or capturing session data — and it has been used in targeted espionage rather than commodity attacks. Anyone running Roundcube before 1.4.15, 1.5.x before 1.5.5, or 1.6.x before 1.6.4 is affected, including Roundcube packages shipped by Debian and Fedora. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-10-26, the Winter Vivern espionage group is reported to have exploited it as a zero-day against government entities, and EPSS puts the 30-day exploitation probability at ~76% (99th percentile).

Do: Upgrade to Roundcube 1.6.4, or 1.5.5 on the 1.5.x branch and 1.4.15 on the 1.4.x branch; apply the corresponding patched roundcube packages for Debian or Fedora. Per the CISA KEV required action, apply vendor mitigations or discontinue use if patching is unavailable. Hunt for compromise by reviewing webmail logs and stored messages for crafted SVG/HTML emails sent around the exploitation window, and review sessions for signs of hijacking.

5.476% KEV PoC
  • Roundcube Webmail All versions before 1.4.15; 1.5.x before 1.5.5; 1.6.x before 1.6.4
  • Debian Linux (roundcube webmail package) Debian releases shipping Roundcube prior to 1.4.15 / 1.5.5 / 1.6.4
  • Fedora (roundcube webmail package) Fedora releases shipping Roundcube prior to 1.4.15 / 1.5.5 / 1.6.4
largetens of thousands of internet-exposed Roundcube servers; plausibly 100k+ end users, unknown precisely
Full article325 words · extracted from helpnetsecurity.com · click to collapse

The Winter Vivern APT group has been exploiting a zero-day vulnerability (CVE-2023-5631) in Roundcube webmail servers to spy on email communications of European governmental entities and a think tank, according to ESET researchers.

CVE-2023-5631

“Exploitation of the XSS vulnerability can be done remotely by sending a specially crafted email message,” the researchers noted. “No manual interaction other than viewing the message in a web browser is required.”

Exploting CVE-2023-5631

Roundcube is an open-source browser-based email client with application-like user interface.

CVE-2023-5631 is a cross-site scripting (XSS) vulnerability in Roundcube’s server-side script rcube_washtml.php, which can be triggered to load arbitrary JavaScript code via an HTML e-mail message with a specially crafted SVG document.

On October 11, 2023, the Winter Vivern hackers sent out to their targets an email impersonating the “Microsoft Accounts Team”, carrying an SVG tag containing a base64-encoded payload – the exploit script.

CVE-2023-5631

The malicious email (Source: ESET)

In the final stage of the attack, the attackers loaded another JavaScript payload that lists folders and emails in the current Roundcube account and exfiltrate email messages to the attackers’ C2 server.

What to do?

“Winter Vivern has stepped up its operations by using a zero-day vulnerability in Roundcube. Previously, it was using known vulnerabilities in Roundcube [CVE-2020-35730] and Zimbra [CVE-2022-27926], for which proofs of concept are available online,” ESET researchers said.

“We believe with low confidence that Winter Vivern is linked to MoustachedBouncer, a sophisticated Belarus-aligned group that we first published about in August, 2023.”

CVE-2023-5631 has been reported to the Roundcube team separately by Matthieu Faou (ESET) and Denys Klymenko, and has been patched a few days after. It affects Roundcube versions 1.6.x before 1.6.4, 1.5.x before 1.5.5, and 1.4.x before 1.4.15.

Admins are advised to upgrade their installation to one of the fixed versions as soon as possible. If they believe they may have been targeted in these attacks, they should also look for indicators of compromise (provided by ESET).

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/10/25/roundcube-webmail-zero-day-exploited-to-spy-on-government-entities-cve-2023-5631/