ZeroHour
Security Affairspublished ()ingested @securityaffairs

CISA adds Zimbra bug to Known Exploited Vulnerabilities Catalog

criticalExploit / PoC exploited in the wildimportance 60CVE-2022-27924

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-27924
Unauthenticated Memcache Command Injection in Synacor Zimbra Collaboration Suite

Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 pass unauthenticated network input to memcache without escaping, allowing a remote attacker to inject arbitrary memcache commands (CWE-74). By sending crafted requests to Zimbra's exposed web/mail services, an attacker can poison the cache and overwrite arbitrary cached entries — a high-severity integrity impact that, in reported campaigns, has been used to tamper with cached data and steal users' login credentials. Any organization running unpatched ZCS 8.8.15 or 9.0 is affected, including the enterprise, ISP, and government mail deployments that make up Zimbra's installed base. Exploitation is ongoing and widespread: the flaw was added to CISA's Known Exploited Vulnerabilities Catalog on 2022-08-04 after mass exploitation, with known ransomware use, and EPSS assigns an 85.4% probability of exploitation within 30 days (100th percentile).

Do: Apply the latest Zimbra patches for the 8.8.15 and 9.0 branches per the vendor's instructions, as required by CISA's KEV entry. As an interim mitigation, restrict memcache access (default TCP port 11211) so it cannot be reached through untrusted interfaces or the exposed mail/web services. Given known ransomware use, prioritize internet-facing Zimbra servers and review mail/web logs for signs of memcache command injection or cache tampering.

7.585% KEV ransomware
  • Synacor Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0
mass≈50,000–100,000 internet-exposed Zimbra servers; total user base plausibly in the millions
Full article345 words · extracted from securityaffairs.com · click to collapse

US Critical Infrastructure Security Agency (CISA) adds a recently disclosed flaw in the Zimbra email suite to its Known Exploited Vulnerabilities Catalog.

The Cybersecurity & Infrastructure Security Agency (CISA) has added a recently disclosed flaw in the Zimbra email suite, tracked as CVE-2022-27924, to its Known Exploited Vulnerabilities Catalog.

In middle June, researchers from Sonarsource discovered the high-severity vulnerability impacting the Zimbra email suite, tracked as CVE-2022-27924 (CVSS score: 7.5). It can be exploited by an unauthenticated attacker to steal login credentials of users without user interaction.

“Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These memcache commands becomes unescaped, causing an overwrite of arbitrary cached entries.” reads the advisory published by NIST.

Once obtained the login credentials, attackers can access the victims’ mailboxes and potentially escalate their access to targeted organizations.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts recommend also private organizations review the Catalog and address the vulnerabilities in their infrastructure.

The researchers published a video PoC that demonstrates how an unauthenticated attacker can steal the password of a known user of a targeted instance.

https://youtu.be/GIgHZrPrGug

The vulnerability is triggered the next time the victim uses a mail client to connect to the Zimbra server of a target organization.

Threat actors, which know the victims’ email addresses, can overwrite an entry in the cache to forward all IMAP traffic to an attacker-controlled server, including the cleartext credentials of a targeted user.

Zimbra addressed the issue on May 10, 2022, with the release of versions 8.8.15 P31.1 and 9.0.0 P24.1.

CISA orders federal agencies to fix the issue by August 25, 2022.

CISA hasn’t shared technical details of the attacks that exploit the Zimbra flaw.

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, Zimbra)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/134058/security/zimbra-known-exploited-vulnerabilities-catalog.html