CISA adds recently disclosed Zimbra bug to its Exploited Vulnerabilities Catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2014-6352 | Remote Code Execution in Microsoft Windows via Crafted OLE Objects (CVE-2014-6352) CVE-2014-6352 is a code injection vulnerability (CWE-94) in the way Microsoft Windows processes Object Linking and Embedding (OLE) objects, the mechanism used to embed linked or embedded content such as links, charts, or multimedia inside documents. An attacker triggers the flaw by delivering a file containing a crafted OLE object — typically an Office document such as a presentation — and persuading a user to open it; successful exploitation allows the attacker to execute arbitrary code in the context of the logged-in user, potentially giving them control of the endpoint for data theft or as a foothold for lateral movement. The vulnerability affects Microsoft Windows systems for which Microsoft shipped fixes in its November 2014 updates, so any unpatched or legacy Windows client or server remains exposed. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-02-25), confirming it has been used in real-world attacks, and its EPSS score of 77.6% places it in the top percentile for likely exploitation; no public proof-of-concept is recorded in the current data. Do: Apply Microsoft's November 2014 security updates addressing this Windows OLE vulnerability across all Windows clients and servers per vendor instructions, prioritizing legacy and internet-reachable systems. Inventory the estate for missing patches, and in the interim restrict users from opening untrusted Office documents and email attachments, since exploitation requires the file to be opened. Track the CISA KEV required action and confirm remediation evidence for this entry. | — | 78% | KEV |
| masshundreds of millions of Windows installations worldwide (Windows is near-universal on enterprise desktops and servers) | |
| CVE-2017-0222 | Memory Corruption RCE in Microsoft Internet Explorer CVE-2017-0222 is a remote code execution flaw in Microsoft Internet Explorer caused by improper access to objects in memory (CWE-119), which can corrupt memory in a way that allows arbitrary code execution. It is triggered remotely, typically when a user is persuaded to view attacker-controlled web content in Internet Explorer. A successful attack runs code in the context of the current user, so the attacker gains that user's privileges and potentially full control of the workstation if the user has elevated rights. Anyone running affected builds of Internet Explorer is exposed, which historically means the very large base of Windows desktops that shipped with IE. Exploitation is confirmed in the wild — CISA added the CVE to its KEV catalog on 2022-02-25 — while no public proof-of-concept is known and ransomware use is unknown; EPSS estimates a 29.6% chance of exploitation in the next 30 days (98th percentile). Do: Apply the Microsoft cumulative security update for Internet Explorer that fixes this issue (released with the April 2017 Patch Tuesday, or any later cumulative IE update) on all Windows systems that still run IE, prioritizing legacy and internet-facing machines. Because CISA's KEV listing in February 2022 shows the flaw was still being exploited years after patching, audit Windows 7/8.1 and Windows Server estates for unpatched IE and migrate users to Microsoft Edge (with IE mode if needed). As interim mitigations, restrict or disable legacy IE, warn users about opening untrusted links, and verify current IE patch levels before patching. | 8.8 | 30% | KEV |
| masshundreds of millions of Windows endpoints (IE was bundled by default on Windows desktops of the era) | |
| CVE-2017-8570 | Remote Code Execution in Microsoft Office via Malicious PPSX Files (CVE-2017-8570) CVE-2017-8570 is a remote code execution vulnerability in Microsoft Office caused by improper handling of embedded OLE objects (composite monikers) in memory, and it is tracked separately from the related CVE-2017-0243. An attacker triggers it by embedding a crafted moniker object in a document, most commonly a PowerPoint .ppsx slide-show file, and persuading a user to open it; the CVSS vector confirms user interaction is required. Successful exploitation lets the attacker run arbitrary code with the victim's privileges, enabling malware delivery, data theft, and follow-on activity. Any user or organization running affected Office builds that open untrusted documents is in scope, and public reporting ties the bug to high-volume maldoc toolkits (e.g., EtterSilent, ThreadKit) and targeted attacks, including one against Ukrainian organizations. Exploitation is confirmed in the wild: CISA added it to the KEV catalog on 2022-02-25, EPSS puts the 30-day exploitation probability at 89.9% (100th percentile), and public PoCs exist. Do: Apply Microsoft's June 2017 (or later) security updates to all Office installations and audit the estate for outdated builds, since CISA KEV and EPSS data show this bug is still exploited years after the patch. As an interim mitigation, block or sandbox .ppsx (PowerPoint Show) email attachments, which are the primary delivery vector, and warn users about Office files triggering embedded object content. Prioritize remediation per CISA's KEV required action: apply updates per vendor instructions. | 7.8 | 90% | KEV PoC ×2 |
| masshundreds of millions of users potentially affected (Office install base exceeds 1 billion; practical exposure limited to systems not updated since mid-2017) | |
| CVE-2022-24682 | Cross-Site Scripting in Synacor Zimbra Collaboration Suite Calendar Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (CWE-79) flaw with improper encoding/escaping (CWE-116) in its Calendar feature, allowing an attacker to execute arbitrary code. The flaw is triggered through the Calendar functionality, where attacker-supplied content is rendered without proper encoding, enabling script/code execution in the context of affected ZCS deployments. A successful attacker can execute arbitrary code in the targeted environment, and CISA notes known ransomware use in the wild. Organizations running Synacor ZCS are affected; the specific affected version ranges are not stated in the available data. The vulnerability was added to the CISA Known Exploited Vulnerabilities catalog on 2022-02-25 with a 30.9% EPSS probability of exploitation within 30 days, though no public proof-of-concept is known. Do: Apply updates per vendor instructions, as required by the CISA KEV listing. Because ransomware use is known, prioritize patching internet-facing ZCS servers, review Zimbra mailbox/Calendar logs for signs of malicious items or unauthorized access, and confirm users' sessions and accounts have not been compromised. Until patched, treat untrusted calendar invites as untrusted input and limit exposure of the ZCS web interface. | 6.1 | 31% | KEV ransomware PoC |
| largetens of thousands of internet-exposed Zimbra servers (public scans have shown roughly 50,000+ ZCS instances online) |
Full article292 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananMar 01, 2022
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) expanded its Known Exploited Vulnerabilities Catalog to include a recently disclosed zero-day flaw in the Zimbra email platform citing evidence of active exploitation in the wild.
Tracked as CVE-2022-24682 (CVSS score: 6.1), the issue concerns a cross-site scripting (XSS) vulnerability in the Calendar feature in Zimbra Collaboration Suite that could be abused by an attacker to trick users into downloading arbitrary JavaScript code simply by clicking a link to exploit URLs in phishing messages.
The Known Exploited Vulnerabilities Catalog is a repository of security flaws that have been seen abused by threat actors in attacks and that are required to be patched by Federal Civilian Executive Branch (FCEB) agencies.
The vulnerability came to light on February 3, 2022, when cybersecurity firm Volexity identified a series of targeted spear-phishing campaigns aimed at European government and media entities that leveraged the aforementioned flaw to gain unauthorized access to victim's mailboxes and plant malware.
Volexity is tracking the actor under the moniker "TEMP_HERETIC," with the attacks impacting the open-source edition of Zimbra running version 8.8.15. Zimbra has since pushed out a hotfix (version 8.8.15 P30) to remediate the flaw.
Due to the potential impact of this vulnerability, CISA has given federal agencies until March 11, 2022, to apply the security updates. In addition to CVE-2022-24682, CISA has also added the following three vulnerabilities to the catalog –
- CVE-2017-8570 (CVSS score: 7.8) – Microsoft Office Remote Code Execution Vulnerability
- CVE-2017-0222 (CVSS score: 7.5) – Microsoft Internet Explorer Memory Corruption Vulnerability
- CVE-2014-6352 (CVSS score: N/A) – Microsoft Windows Code Injection Vulnerability
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/02/cisa-adds-recently-disclosed-zimbra-bug.html