Hackers target Greece, Tunisia, Moldova, Vietnam and Pakistan with Zimbra zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-24682 | Cross-Site Scripting in Synacor Zimbra Collaboration Suite Calendar Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (CWE-79) flaw with improper encoding/escaping (CWE-116) in its Calendar feature, allowing an attacker to execute arbitrary code. The flaw is triggered through the Calendar functionality, where attacker-supplied content is rendered without proper encoding, enabling script/code execution in the context of affected ZCS deployments. A successful attacker can execute arbitrary code in the targeted environment, and CISA notes known ransomware use in the wild. Organizations running Synacor ZCS are affected; the specific affected version ranges are not stated in the available data. The vulnerability was added to the CISA Known Exploited Vulnerabilities catalog on 2022-02-25 with a 30.9% EPSS probability of exploitation within 30 days, though no public proof-of-concept is known. Do: Apply updates per vendor instructions, as required by the CISA KEV listing. Because ransomware use is known, prioritize patching internet-facing ZCS servers, review Zimbra mailbox/Calendar logs for signs of malicious items or unauthorized access, and confirm users' sessions and accounts have not been compromised. Until patched, treat untrusted calendar invites as untrusted input and limit exposure of the ZCS web interface. | 6.1 | 31% | KEV ransomware PoC |
| largetens of thousands of internet-exposed Zimbra servers (public scans have shown roughly 50,000+ ZCS instances online) | |
| CVE-2023-37580 | Stored Cross-Site Scripting (XSS) in Synacor Zimbra Collaboration Suite (ZCS) CVE-2023-37580 is a cross-site scripting flaw (CWE-79) in Synacor Zimbra Collaboration Suite's webmail interface, publicly described as a stored XSS in which attacker-supplied content persists and executes in victims' browsers. An attacker delivers crafted content (typically a malicious email or message) that, when viewed by a user in the Zimbra webmail client, runs attacker-controlled JavaScript within that user's authenticated session. Successful execution impacts the confidentiality and integrity of the victim's mailbox: the attacker can steal session cookies or credentials, read or alter mail, and act as the user. Any organization running a vulnerable ZCS release is affected, including self-hosted on-premises deployments and providers hosting Zimbra webmail for customers. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2023-07-27, confirming exploitation in the wild (ransomware association unknown), while no public proof-of-concept is posted, CVSS is not yet scored, and EPSS assigns a 46.7% probability of exploitation within 30 days (99th percentile). Do: Apply the latest ZCS patch release addressing CVE-2023-37580 per the Synacor/Zimbra security advisory, as CISA's required action directs, or discontinue use of the affected deployment if mitigation is unavailable; because the flaw is on the KEV list, prioritize internet-facing webmail servers. While patching is pending, restrict webmail exposure (VPN or IP allowlisting) and review webmail and mail-delivery logs for signs of exploitation. Confirm the installed ZCS version and applied patch level against the vendor advisory, since this dataset does not list fixed version numbers. | 6.1 | 47% | KEV |
| masstens of thousands of internet-exposed Zimbra servers (order of 10,000–100,000) serving millions of mailboxes in aggregate (estimate) |
Full article583 words · extracted from therecord.media · click to collapse
Hackers exploited a vulnerability in Zimbra’s email product to attack government agencies in Greece, Tunisia, Moldova, Vietnam and Pakistan, Google researchers have discovered. Google’s Threat Analysis Group (TAG) first discovered the bug, classified as CVE-2023-37580, in June. Beginning that month, four different groups exploited the zero-day to target Zimbra Collaboration, an email server many organizations use to host their email. The bug is a cross-site scripting (XSS) vulnerability, which allows hackers to inject malicious scripts into a victim website. Google said the attacks on government organizations in Greece occurred on June 29, while Moldova and Tunisia were targeted on July 11. Vietnam and Pakistan were attacked on July 20 and August 25, respectively. The hackers stole email information, user credentials and authentication tokens. Zimbra released a hotfix for the issue on GitHub on July 5 and published an advisory with remediation guidance on July 13. An official patch was pushed out by July 25. “TAG observed three threat groups exploiting the vulnerability prior to the release of the official patch, including groups that may have learned about the bug after the fix was initially made public on Github,” Google officials said. “TAG discovered a fourth campaign using the XSS vulnerability after the official patch was released. Three of these campaigns began after the hotfix was initially made public highlighting the importance of organizations applying fixes as quickly as possible.” The attack on Greece began with an email carrying a malicious link. When clicked during a logged-in Zimbra session, the hacker was given access to the user’s emails and attachments. Hackers could also use it to set up an auto-forwarding rule to an attacker-controlled email address. The second campaign targeting governments in Moldova and Tunisia was attributed to Winter Vivern, a notorious hacking group with suspected ties to Russia. The group has previously been accused of targeting organizations in Ukraine, Poland and India. Last month, the group was caught exploiting a zero-day vulnerability affecting another popular webmail service used by governments across Europe. In the attacks on Moldova and Tunisia, the malicious URLs in the email “contained a unique official email address for specific organizations in those governments.” A third campaign targeting a government organization in Vietnam involved attempts to phish for user credentials. “In this case, the exploit url pointed to a script that displayed a phishing page for users’ webmail credentials and posted stolen credentials to a url hosted on an official government domain that the attackers likely compromised,” Google said. The fourth attack, on a government organization in Pakistan, involved an attempt to steal Zimbra authentication tokens. Google said the hacks were examples of how attackers monitor open-source repositories where fixes for vulnerabilities are posted but not yet released to users. The researchers added that this is the second vulnerability affecting Zimbra mail servers that has been used in attacks on governments, following exploitation in 2022 of another XSS vulnerability, CVE-2022-24682. “The regular exploitation of XSS vulnerabilities in mail servers also shows a need for further code auditing of these applications, especially for XSS vulnerabilities,” they said. “We urge users and organizations to apply patches quickly and keep software fully up-to-date for their full protection.”
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/hackers-target-govts-with-zimbra-zero