ZeroHour
Infosecurity Magazinepublished ()ingested Alessandro Mascellino

Zimbra RCE Vulnerability Exploited Without Admin Privileges

criticalVulnerability exploited in the wildimportance 60CVE-2022-27925CVE-2022-37042

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-27925
Authenticated Path Traversal File Upload Leading to RCE in Zimbra Collaboration Suite

CVE-2022-27925 is a directory traversal flaw (CWE-22) in the mailbox import (mboximport) functionality of Synacor Zimbra Collaboration Suite (ZCS), which accepts a ZIP archive and extracts files from it without properly validating paths. An authenticated user with administrator rights can trigger the flaw by submitting a malicious ZIP archive, causing arbitrary files to be written outside the intended directory. By planting attacker-controlled files in arbitrary locations, an attacker can achieve remote code execution on the server. All organizations running ZCS 8.8.15 or 9.0 are potentially affected, and the flaw has been mass-exploited in the wild — CISA added it to the Known Exploited Vulnerabilities catalog on 2022-08-11, ordered civilian agencies to patch it, and ransomware operators and other actors are known to be using it.

Do: Apply the vendor's updates/patches for ZCS 8.8.15 and 9.0 as instructed by Zimbra, per CISA's required action. Limit external access to Zimbra's mailbox import/administration endpoints to trusted networks only, and hunt for indicators of compromise such as unexpected files or webshells in the Zimbra web root, unusual admin activity, and signs of follow-on ransomware deployment.

7.299% KEV ransomware PoC
  • Synacor Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0
largetens of thousands of internet-exposed Zimbra servers serving an estimated hundreds of thousands of users (vendor claims 200,000+ organizational customers)
CVE-2022-37042
Unauthenticated ZIP Path Traversal RCE in Synacor Zimbra Collaboration Suite

CVE-2022-37042 is an authentication bypass combined with a ZIP archive path traversal (CWE-22) in the mboximport functionality of Synacor Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0, and it exists because of an incomplete fix for CVE-2022-27925. An attacker does not need a valid authtoken: by sending an attacker-crafted ZIP archive to the mboximport endpoint, the flaw lets arbitrary files be extracted and written outside the intended directory. Successful file-write primitives on a Zimbra server lead directly to remote code execution, with no privileges or user interaction required (CVSS 3.1: 9.8, AV:N/AC:L/PR:N/UI:N). All internet-reachable ZCS 8.8.15 and 9.0 deployments are in scope, and the flaw has been added to CISA KEV (2022-08-11) with known ransomware use and a 91.9% EPSS exploitation probability. Exploitation is confirmed in the wild at scale: CISA ordered civilian agencies to patch after mass exploitation, and headlines attribute campaigns to both North Korean (No Pineapple) and Chinese state-sponsored (RedHotel) actors.

Do: Immediately apply the current ZCS 8.8.15 and 9.0 patch releases per Synacor/Zimbra vendor instructions, as required by CISA's KEV required action. Until patched, restrict or block unauthenticated access to the mboximport/service extension endpoint (e.g., via firewall or reverse proxy rules) and verify no authtoken-less requests have reached it. Hunt for unexpected files written by the mailbox process, review mailboxd/access logs for ZIP uploads lacking an authtoken, and check for follow-on webshell, lateral-movement, or ransomware artifacts given confirmed ransomware use.

9.892% KEV ransomware PoC
  • Synacor Zimbra Collaboration Suite (ZCS) - mboximport functionality 8.8.15 and 9.0 (incomplete fix for CVE-2022-27925)
largetens of thousands of internet-exposed Zimbra servers (public internet-wide scans show on the order of 10k-100k ZCS instances)
Full article418 words · extracted from infosecurity-magazine.com · click to collapse

A remote-code-execution (RCE) vulnerability affecting Zimbra Collaboration Suite (ZCS) email servers was exploited without valid administrative credentials, unlike previously believed.

The finding come from security researchers at Volexity, who detailed them in an advisory published on Wednesday.

While the RCE issue (tracked CVE-2022-27925) was patched by Zimbra in March 2022, in July and early August 2022 Volexity investigated several instances of victim organizations experiencing serious breaches to their ZCS email servers.

“Initial research into the vulnerability did not uncover any public exploit code, but since a patch had been available for several months, it was reasonable that exploit code could have been developed based on the description of the vulnerability,” read the advisory.

However, one thing that caught the security researchers’ attention was that, in addition to being remotely executable, the vulnerability description clearly stated its exploitation required valid administrator credentials. 

“This added a significant level of difficulty for an attacker to successfully compromise a ZCS instance and made mass exploitation unlikely.”

Further investigation from Volexity then showed signs of remote exploitation but no evidence the attackers had the administrative rights needed to exploit it.

“Subsequent testing by Volexity determined it was possible to bypass authentication when accessing the same endpoint [...] used by CVE-2022-27925,” Volexity said. “This meant that [the flaw] could be exploited without valid administrative credentials, thus making the vulnerability significantly more critical in severity.”

After disclosing the authentication bypass vulnerability (tracked CVE-2022-37042) to Zimbra, the company issued patches for it at the end of July.

Still, the Volexity investigation suggested the vulnerability was being mass exploited with the authentication bypass as early as the end of June 2022, and over 1000 ZCS instances around the world being backdoored and compromised.

“These ZCS instances belong to a variety of global organizations, including government departments and ministries; military branches; worldwide businesses with billions of dollars of revenue, etc.“

Volexity said that affected organizations also included a considerable number of small businesses unlikely to have dedicated IT staff to manage their mail servers, and therefore less prepared to effectively detect and remediate an incident.

In order to verify the presence of web shells on a ZCS instance, Volexity suggested companies compare the list of JSP files on a Zimbra instance with those present by default in Zimbra installations. 

The company’s mail servers were also under the spotlight at the end of June when a flaw in RARlab’s UnRAR utility was discovered that could be exploited to steal emails from individual Zimbra mail user accounts.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/zimbra-rce-exploited-without-admin/