Enterprise IT Support β€’ Bangkok & Nationwide

Technology newsroom

CISA Issues Urgent Warning! 🚨 Global Zimbra Users Must Patch Critical Vulnerability CVE-2022-41352 After Exploitation Detected

CISA has issued an urgent directive for Zimbra administrators worldwide to immediately patch CVE-2022-41352, a Remote Code Execution vulnerability actively exploited by attackers. The advisory recommends installing the cpio utility and restarting services without delay.

Edited by SyncTech Solution Published Source Original source
CISA Issues Urgent Warning! 🚨 Global Zimbra Users Must Patch Critical Vulnerability CVE-2022-41352 After Exploitation Detected

πŸ“Œ Key Highlights:
- The CVE-2022-41352 vulnerability in Zimbra Collaboration Suite (ZCS) has been actively exploited by hackers and is classified as a Remote Code Execution (RCE) severity.
- This issue stems from Zimbra using the insecure pax utility to extract .tar files when cpio is not found on the system, allowing attackers to surreptitiously run malicious code through file uploads.
- CISA has mandated that U.S. federal agencies patch this vulnerability within 3 days and advises all Zimbra administrators to take immediate action.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent directive to all federal agencies to update patches for a high-severity vulnerability in Zimbra Collaboration Suite (ZCS), a popular email and collaboration platform. This vulnerability, identified as CVE-2022-41352, has already been added to the Known Exploited Vulnerabilities (KEV) Catalog, meaning there is clear evidence that hackers are actively exploiting this vulnerability against targets.

Regarding the technical details of CVE-2022-41352, it arises from how ZCS handles compressed attachment files (.tar). Normally, Zimbra uses a utility called cpio to extract files. However, if cpio is not installed on the server, the system defaults to using pax, an alternative tool with a vulnerability. This allows attackers to create a .tar file embedding malicious code. When a user scans this file with an Antivirus program on the Zimbra server, the embedded code is immediately executed, enabling attackers to gain remote control of the server (Remote Code Execution).

πŸ›‘οΈ Remediation and Prevention Guidelines
CISA has set a deadline for federal agencies to patch this vulnerability by October 28, 2022. However, private organizations and general system administrators should also take action as quickly as possible. The simplest and fastest initial fix is to install the cpio package on servers running Zimbra (e.g., using the command `sudo apt install cpio` on Debian/Ubuntu or `sudo yum install cpio` on CentOS/RHEL). After installation, restart all Zimbra services to ensure the system uses the more secure cpio for operations.

As Zimbra is a widely used platform by thousands of organizations globally, both public and private, leaving this vulnerability unpatched poses a very high risk of falling victim to attacks. This could lead to the leakage of critical data, ransomware demands, or the hijacking of servers to be used as a base for further attacks. Therefore, all system administrators should promptly check and implement the fix immediately.

πŸ’¬ Who among you uses Zimbra? Have you checked and updated already? Feel free to share your status in the comments below!

Let’s build what’s next

Better IT starts with understanding your business.

Tell our engineers what you need and receive an initial recommendation at no cost.