Security News > 2022 > August > Researchers Warn of Ongoing Mass Exploitation of Zimbra RCE Vulnerability

Researchers Warn of Ongoing Mass Exploitation of Zimbra RCE Vulnerability
2022-08-12 06:14

The U.S. Cybersecurity and Infrastructure Security Agency on Thursday added two flaws to its Known Exploited Vulnerabilities Catalog, citing evidence of active exploitation.

The two high-severity issues relate to weaknesses in Zimbra Collaboration, both of which could be chained to achieve unauthenticated remote code execution on affected email servers -.

"If you are running a Zimbra version that is older than Zimbra 8.8.15 patch 33 or Zimbra 9.0.0 patch 26 you should update to the latest patch as soon as possible," Zimbra warned earlier this week.

CISA has not shared any information on the attacks exploiting the flaws but cybersecurity firm Volexity described mass in-the-wild exploitation of Zimbra instances by an unknown threat actor.

Volexity said "It was possible to bypass authentication when accessing the same endpoint used by CVE-2022-27925," and that the flaw "Could be exploited without valid administrative credentials, thus making the vulnerability significantly more critical in severity."

"When combined with a separate bug it became an unauthenticated RCE exploit that made remote exploitation trivial."


News URL

https://thehackernews.com/2022/08/researchers-warn-of-ongoing-mass.html

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2022-04-21 CVE-2022-27925 Path Traversal vulnerability in Zimbra Collaboration 8.8.15/9.0.0
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it.
network
low complexity
zimbra CWE-22
7.2

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Zimbra 7 0 39 16 8 63