ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Researchers Warn of Ongoing Mass Exploitation of Zimbra RCE Vulnerability

criticalVulnerability exploited in the wildimportance 60CVE-2022-27925CVE-2022-37042CVE-2022-27924

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-27924
+1 in the same advisory: …27925
Unauthenticated Memcache Command Injection in Synacor Zimbra Collaboration Suite

Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 pass unauthenticated network input to memcache without escaping, allowing a remote attacker to inject arbitrary memcache commands (CWE-74). By sending crafted requests to Zimbra's exposed web/mail services, an attacker can poison the cache and overwrite arbitrary cached entries — a high-severity integrity impact that, in reported campaigns, has been used to tamper with cached data and steal users' login credentials. Any organization running unpatched ZCS 8.8.15 or 9.0 is affected, including the enterprise, ISP, and government mail deployments that make up Zimbra's installed base. Exploitation is ongoing and widespread: the flaw was added to CISA's Known Exploited Vulnerabilities Catalog on 2022-08-04 after mass exploitation, with known ransomware use, and EPSS assigns an 85.4% probability of exploitation within 30 days (100th percentile).

Do: Apply the latest Zimbra patches for the 8.8.15 and 9.0 branches per the vendor's instructions, as required by CISA's KEV entry. As an interim mitigation, restrict memcache access (default TCP port 11211) so it cannot be reached through untrusted interfaces or the exposed mail/web services. Given known ransomware use, prioritize internet-facing Zimbra servers and review mail/web logs for signs of memcache command injection or cache tampering.

7.5
group max
85% KEV ransomware
  • Synacor Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0
mass≈50,000–100,000 internet-exposed Zimbra servers; total user base plausibly in the millions
CVE-2022-37042
Unauthenticated ZIP Path Traversal RCE in Synacor Zimbra Collaboration Suite

CVE-2022-37042 is an authentication bypass combined with a ZIP archive path traversal (CWE-22) in the mboximport functionality of Synacor Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0, and it exists because of an incomplete fix for CVE-2022-27925. An attacker does not need a valid authtoken: by sending an attacker-crafted ZIP archive to the mboximport endpoint, the flaw lets arbitrary files be extracted and written outside the intended directory. Successful file-write primitives on a Zimbra server lead directly to remote code execution, with no privileges or user interaction required (CVSS 3.1: 9.8, AV:N/AC:L/PR:N/UI:N). All internet-reachable ZCS 8.8.15 and 9.0 deployments are in scope, and the flaw has been added to CISA KEV (2022-08-11) with known ransomware use and a 91.9% EPSS exploitation probability. Exploitation is confirmed in the wild at scale: CISA ordered civilian agencies to patch after mass exploitation, and headlines attribute campaigns to both North Korean (No Pineapple) and Chinese state-sponsored (RedHotel) actors.

Do: Immediately apply the current ZCS 8.8.15 and 9.0 patch releases per Synacor/Zimbra vendor instructions, as required by CISA's KEV required action. Until patched, restrict or block unauthenticated access to the mboximport/service extension endpoint (e.g., via firewall or reverse proxy rules) and verify no authtoken-less requests have reached it. Hunt for unexpected files written by the mailbox process, review mailboxd/access logs for ZIP uploads lacking an authtoken, and check for follow-on webshell, lateral-movement, or ransomware artifacts given confirmed ransomware use.

9.892% KEV ransomware PoC
  • Synacor Zimbra Collaboration Suite (ZCS) - mboximport functionality 8.8.15 and 9.0 (incomplete fix for CVE-2022-27925)
largetens of thousands of internet-exposed Zimbra servers (public internet-wide scans show on the order of 10k-100k ZCS instances)
Full article398 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananAug 12, 2022

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added two flaws to its Known Exploited Vulnerabilities Catalog, citing evidence of active exploitation.

The two high-severity issues relate to weaknesses in Zimbra Collaboration, both of which could be chained to achieve unauthenticated remote code execution on affected email servers -

  • CVE-2022-27925 (CVSS score: 7.2) - Remote code execution (RCE) through mboximport from authenticated user (fixed in versions 8.8.15 Patch 31 and 9.0.0 Patch 24 released in March)
  • CVE-2022-37042 - Authentication bypass in MailboxImportServlet (fixed in versions 8.8.15 Patch 33 and 9.0.0 Patch 26 released in August)

"If you are running a Zimbra version that is older than Zimbra 8.8.15 patch 33 or Zimbra 9.0.0 patch 26 you should update to the latest patch as soon as possible," Zimbra warned earlier this week.

CISA has not shared any information on the attacks exploiting the flaws but cybersecurity firm Volexity described mass in-the-wild exploitation of Zimbra instances by an unknown threat actor.

In a nutshell, the attacks involve taking advantage of the aforementioned authentication bypass flaw to gain remote code execution on the underlying server by uploading arbitrary files.

Volexity said "it was possible to bypass authentication when accessing the same endpoint (mboximport) used by CVE-2022-27925," and that the flaw "could be exploited without valid administrative credentials, thus making the vulnerability significantly more critical in severity."

It also singled out over 1,000 instances globally that were backdoored and compromised using this attack vector, some of which belong to government departments and ministries; military branches; and companies with billions of dollars of revenue.

The attacks, which transpired as recently as the end of June 2022, also involved the deployment of web shells to maintain long-term access to the infected servers. Top countries with the most compromised instances include the U.S., Italy, Germany, France, India, Russia, Indonesia, Switzerland, Spain, and Poland.

"CVE-2022-27925 was originally listed as an RCE exploit requiring authentication," Volexity said. "When combined with a separate bug, however, it became an unauthenticated RCE exploit that made remote exploitation trivial."

The disclosure comes a week after CISA added another Zimbra-related bug, CVE-2022-27924, to the catalog, which, if exploited, could allow attackers to steal cleartext credentials from users of the targeted instances.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/08/researchers-warn-of-ongoing-mass.html