ZeroHour
The Recordpublished ()ingested

CISA orders civilian agencies to patch Zimbra bug after mass exploitation

criticalVulnerability exploited in the wildimportance 60CVE-2022-37042CVE-2022-27925CVE-2022-27924

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-27924
+1 in the same advisory: …27925
Unauthenticated Memcache Command Injection in Synacor Zimbra Collaboration Suite

Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 pass unauthenticated network input to memcache without escaping, allowing a remote attacker to inject arbitrary memcache commands (CWE-74). By sending crafted requests to Zimbra's exposed web/mail services, an attacker can poison the cache and overwrite arbitrary cached entries — a high-severity integrity impact that, in reported campaigns, has been used to tamper with cached data and steal users' login credentials. Any organization running unpatched ZCS 8.8.15 or 9.0 is affected, including the enterprise, ISP, and government mail deployments that make up Zimbra's installed base. Exploitation is ongoing and widespread: the flaw was added to CISA's Known Exploited Vulnerabilities Catalog on 2022-08-04 after mass exploitation, with known ransomware use, and EPSS assigns an 85.4% probability of exploitation within 30 days (100th percentile).

Do: Apply the latest Zimbra patches for the 8.8.15 and 9.0 branches per the vendor's instructions, as required by CISA's KEV entry. As an interim mitigation, restrict memcache access (default TCP port 11211) so it cannot be reached through untrusted interfaces or the exposed mail/web services. Given known ransomware use, prioritize internet-facing Zimbra servers and review mail/web logs for signs of memcache command injection or cache tampering.

7.5
group max
85% KEV ransomware
  • Synacor Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0
mass≈50,000–100,000 internet-exposed Zimbra servers; total user base plausibly in the millions
CVE-2022-37042
Unauthenticated ZIP Path Traversal RCE in Synacor Zimbra Collaboration Suite

CVE-2022-37042 is an authentication bypass combined with a ZIP archive path traversal (CWE-22) in the mboximport functionality of Synacor Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0, and it exists because of an incomplete fix for CVE-2022-27925. An attacker does not need a valid authtoken: by sending an attacker-crafted ZIP archive to the mboximport endpoint, the flaw lets arbitrary files be extracted and written outside the intended directory. Successful file-write primitives on a Zimbra server lead directly to remote code execution, with no privileges or user interaction required (CVSS 3.1: 9.8, AV:N/AC:L/PR:N/UI:N). All internet-reachable ZCS 8.8.15 and 9.0 deployments are in scope, and the flaw has been added to CISA KEV (2022-08-11) with known ransomware use and a 91.9% EPSS exploitation probability. Exploitation is confirmed in the wild at scale: CISA ordered civilian agencies to patch after mass exploitation, and headlines attribute campaigns to both North Korean (No Pineapple) and Chinese state-sponsored (RedHotel) actors.

Do: Immediately apply the current ZCS 8.8.15 and 9.0 patch releases per Synacor/Zimbra vendor instructions, as required by CISA's KEV required action. Until patched, restrict or block unauthenticated access to the mboximport/service extension endpoint (e.g., via firewall or reverse proxy rules) and verify no authtoken-less requests have reached it. Hunt for unexpected files written by the mailbox process, review mailboxd/access logs for ZIP uploads lacking an authtoken, and check for follow-on webshell, lateral-movement, or ransomware artifacts given confirmed ransomware use.

9.892% KEV ransomware PoC
  • Synacor Zimbra Collaboration Suite (ZCS) - mboximport functionality 8.8.15 and 9.0 (incomplete fix for CVE-2022-27925)
largetens of thousands of internet-exposed Zimbra servers (public internet-wide scans show on the order of 10k-100k ZCS instances)
Full article687 words · extracted from therecord.media · click to collapse

The Cybersecurity and Infrastructure Security Agency added two vulnerabilities found in products from digital collaboration platform Zimbra after a cybersecurity company reported mass exploitation of the bugs throughout July and in early August. 

On Wednesday, Zimbra released an advisory urging its customers running older versions of the software to immediately install updates. CISA ordered all civilian agencies to install the patches before September 1. 

Zimbra’s Barry De Graaff said the fixes address an authentication bypass in MailboxImportServlet – CVE-2022-37042 and CVE-2022-27925. 

Cybersecurity firm Volexity published a report this week noting that it worked on multiple incidents where the victim organization experienced serious breaches to their Zimbra Collaboration Suite (ZCS) email servers through exploitation of CVE-2022-27925, a remote-code-execution vulnerability in ZCS.

Volexity explained that CVE-2022-27925 was patched in March and was very difficult to exploit because it required valid administrator credentials.

CVE-2022-27925 facilitated writing #webshells to disk and was patched months ago. However, it was deemed lower priority because it required admin creds to exploit. Enter CVE-2022-37042 ... which bypassed authentication making this a CRITICAL and trivial to exploit vulnerability.

— Steven Adair (@stevenadair) August 11, 2022

But through its investigations, the company’s researchers found exploitation with no evidence the attackers had the prerequisite authenticated administrative sessions needed to exploit it. 

They reported the issue to Zimbra, which patched the vulnerability in July and assigned the issue a new name: CVE-2022-37042.

“Through multiple investigations, evidence was uncovered indicating that CVE-2022-27925 was being mass exploited with the authentication bypass as early the end of June 2022. Volexity believes this vulnerability was exploited in a manner consistent with what it saw with Microsoft Exchange 0-day vulnerabilities it discovered in early 2021,” the company said.  

“Initially it was exploited by espionage-oriented threat actors, but was later picked up by other threat actors and used in mass-exploitation attempts.”

The company later scanned the internet, finding more than 1,000 ZCS instances around the world that were backdoored and compromised, but Volexity researchers noted that it is likely that the true number of compromised servers is higher.

Nearly 150 were found in the U.S. while over 100 are in Italy and 90 are in Denmark. Volexity said it notified local CERTs of compromised Zimbra instances in their constituency.

Geographic distribution of compromised Zimbra servers (by geolocation of IP) Image: Volexity

The company added that the bug may not be the only exploit for ZCS in use by hackers. CISA itself warned on August 4 that CVE-2022-27924, another ZCS bug, was being exploited and ordered civilian agencies to patch it by August 25. 

CISA likely added the bug to its list due to “other active incidents involving breaches beginning with ZCS compromise,” according to Volexity. 

“If your organization runs ZCS and did not apply patches 8.8.15P31 or 9.0.0P24 before the end of May 2022, you should consider your ZCS instance may be compromised (and thus all data on it, including email content, may be stolen) and perform a full analysis of the server,” Volexity explained. 

“Based on limited testing by Volexity, it seems that patching ZCS instances to the newest version may remove webshells placed in some directories. However, if an attacker installed any second-stage or persistent malware (run via cron), then patching your ZCS instance is insufficient to remediate the compromise.”

Netenrich’s John Bambenek said his main concern with the bugs uncovered recently is centered on how many organizations use Zimbra.

Collaboration tools often have valuable trade secrets, however, the casual conversations that occur there often obscure the seriousness of the value that resides there, Bambenek said. 

“In addition, many Zimbra users are smaller, therefore they likely lack security teams and even IT teams may be understaffed so they may not even know there is a problem, much less have the time and availability to address patching,” he explained. 

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisa-orders-civilian-agencies-to-patch-zimbra-bug-after-mass-exploitation