
Zimbra <9.0.0.p27 リモートコード実行
CVE-2022-41352 は、脆弱な
cpioバージョンを使用していることに起因する、Zimbra メールサーバーにおける任意ファイル書き込みの脆弱性です。
影響を受ける Zimbra バージョン:
(詳細はパッチノートを参照してください。)
修正方法:
脆弱性を修正するには、最新のパッチ(それぞれ 9.0.0.p27 および 8.8.15.p34)を適用するか、pax をインストールしてサーバーを再起動してください。
使用方法:
フラグを使用するか、スクリプト内のデフォルト設定(上部の設定ブロック)を手動で変更できます。
ヘルプは -h を使用してください。
$ python cve-2022-41352.py -h
$ vi cve-2022-41352.py
# Change the config items.
$ python cve-2022-41352.py manual
# This will create an attachment that you can then send to the target server.
# The recipient does not necessarily have to exist - if the email with the attachment is parsed by the server the arbitrary file write in cpio will be triggered.
例:
(上記のスクリーンショットはメール本文の誤った出力を示していますが、修正済みです。)
デモ: