Technology newsroom
Urgent Alert! Critical Zimbra Vulnerability Under Active Attack, Administrators Must Update Patches Immediately
CERT Polska warns that a critical vulnerability in Zimbra Collaboration Suite (CVE-2022-27925) is actively being exploited by hackers to compromise servers. Administrators are advised to update patches urgently.
π¨ Urgent! Zimbra Collaboration Suite (ZCS) users, please be aware: a critical vulnerability is under active exploitation.
- The CVE-2022-27925 vulnerability allows attackers to perform Remote Code Execution (RCE) without authentication.
- Active attacks have been confirmed, with CERT Polska and Volexity verifying intrusions via this vulnerability.
- Administrators using ZCS versions 8.8.15 and 9.0 should update to the latest security patches as soon as possible.
CERT Polska, Poland's computer emergency response team, has issued an alert that hackers have begun exploiting a critical security vulnerability in Zimbra Collaboration Suite (ZCS) to launch attacks. The vulnerability is tracked under CVE-2022-27925, a Path Traversal flaw that allows unauthenticated attackers to execute malicious code remotely (Remote Code Execution) on the server.
The nature of this vulnerability's attack involves malicious actors sending specially crafted ZIP files to the target server via the mboximport component, which is responsible for importing email data. The Path Traversal vulnerability allows attackers to place Webshell files in a web-accessible directory, granting complete control over the server. This poses an extremely severe risk for organizations using ZCS.
Zimbra initially released a patch for this vulnerability in May, but it was later found to be incomplete and bypassable (tracked as CVE-2022-37042). As a result, Zimbra had to issue a complete corrective patch again on July 26. Cybersecurity firm Volexity has also confirmed observing real-world attacks exploiting this vulnerability.
π‘οΈ What Administrators Must Do
For administrators using Zimbra Collaboration Suite versions 8.8.15 and 9.0, it is crucial to apply the latest security patches released by Zimbra as soon as possible to prevent attacks and system compromise, which could lead to damage to critical organizational data.
π¬ Does your organization's email system use Zimbra? Have you checked and applied the patches yet?