Thứ Hai, Tháng Hai 6, 2023
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
NATuts
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
No Result
View All Result
NATuts
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
No Result
View All Result
NATuts
No Result
View All Result
Home Tech

Researchers warn of ongoing mass exploitation of Zimbra RCE vulnerability

12 Tháng Tám, 2022
in Tech
0
CISA Adds Zimbra Email Security Vulnerability to its Exploited Vulnerability List
585
SHARES
3.3k
VIEWS
Share on FacebookShare on Twitter

Các bài viết liên quan:

How to get travel insurance

Guide on how to get travel insurance with 4 options

24 Tháng Một, 2023
Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

8 Tháng Một, 2023
5 Best Software to Stream Games

5 Best Software to Stream Games

2 Tháng Một, 2023
IBM Bridge To Cloud For Power

IBM Bridge To Cloud For Power- Everything You Should Know

2 Tháng Một, 2023
Top 10 CRM Software For Construction 

Top 10 CRM Software For Construction Enterprises All The Time

31 Tháng Mười Hai, 2022
What Is IBM Software

What Is IBM Software? 4 Business Segments at IBM You Should Know

26 Tháng Mười Hai, 2022

Zimbra RCE Vulnerability

Organ Network security and American Infrastructure (CISA) on Thursday added two vulnerabilities to its List of Known Exploited Vulnerabilities, citing evidence of active exploitation.

Two high-severity issues related to weaknesses in Zimbra Collaboration, both of these issues can be chained to achieve the remote code execution unauthenticated on affected email servers –

CVE-2022-27925 (CVSS Score: 7.2) – Remote Code Execution (RCE) via mboximport from authenticated users (fixed in versions 8.8.15 Patch 31 and 9.0.0 Patch 24 released in March)
CVE-2022-37042 – Bypass authentication in MailboxImportServlet (fixed in version 8.8.15 Patch 33 and 9.0.0 Patch 26 released in August)

“If you are running a version of Zimbra older than Zimbra 8.8.15 patch 33 or Zimbra 9.0.0 patch 26, you should update to the latest patch as soon as possible,” Zimbra warned earlier this week.

CISA hasn’t shared any information about the attacks exploiting the vulnerability, but cybersecurity firm Volexity has described the mass exploitation of instances of Zimbra in the wild by an unknown threat actor.

In a nutshell, the attacks involve taking advantage of the aforementioned authentication bypass vulnerability to remotely execute code on the underlying server by uploading arbitrary files.

Zimbra RCE Vulnerability

Volexity said that “authentication can be bypassed when accessing the same endpoint (mboximport) used by CVE-2022-27925” and that the vulnerability “can be exploited without valid credentials, due to which makes the vulnerability significantly more severe in severity.”

It also shows more than 1,000 cases globally that have been censored and hacked using this attack vector, some of which belong to government departments and agencies; military branches; and companies with billions of dollars in revenue.

The attacks, which took place as recently as late June 2022, also involved implementing web shells to maintain long-term access to infected servers. The top countries with the most compromised cases include the US, Italy, Germany, France, India, Russia, Indonesia, Switzerland, Spain, and Poland.

“CVE-2022-27925 was originally listed as an RCE exploit that required authentication,” Volexity said. “However, when combined with a separate bug, it becomes an unauthenticated RCE exploit that makes remote mining trivial.”

The disclosure comes a week after CISA added another Zimbra-related bug, CVE-2022-27924, to the category that, if exploited, could allow attackers to steal text credentials obvious from users of the targeted versions.

.

Previous Post

Download CST Studio Suite 2022

Next Post

Who is Big Mouse? Decoding hot trending characters on Social Networks in 2022!

Megusta

Megusta

Related Posts

5 Best Software to Stream Games

5 Best Software to Stream Games

2 Tháng Một, 2023
Top 10 CRM Software For Construction 

Top 10 CRM Software For Construction Enterprises All The Time

31 Tháng Mười Hai, 2022
Instruction how to use OBS streaming software

Features, settings and how to use OBS streaming software through 9 simple steps

25 Tháng Mười Hai, 2022
What is Trans woman?  What is Transgender Women?

What is Trans woman? What is Transgender Women?

23 Tháng Mười Hai, 2022
Christmas gift: Genuine Windows 10 Pro for only $6.63 and Office 2021 for $14.22

Christmas gift: Genuine Windows 10 Pro for only $6.63 and Office 2021 for $14.22

22 Tháng Mười Hai, 2022
How to get 50 free coins of SkyJoy App to redeem

How to get 50 free coins of SkyJoy App to redeem

21 Tháng Mười Hai, 2022
Load More
Next Post
Who is Big Mouse?  Decoding hot trending characters on Social Networks in 2022!

Who is Big Mouse? Decoding hot trending characters on Social Networks in 2022!

Trả lời Hủy

Email của bạn sẽ không được hiển thị công khai. Các trường bắt buộc được đánh dấu *

Bài viết mới

How to get travel insurance
Đời sống

Guide on how to get travel insurance with 4 options

24 Tháng Một, 2023
Software Asset Management for Websites: How to Keep Your Sites Running Smoothly
Phần mềm

Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

8 Tháng Một, 2023
5 Best Software to Stream Games
Software

5 Best Software to Stream Games

2 Tháng Một, 2023
IBM Bridge To Cloud For Power
Software

IBM Bridge To Cloud For Power- Everything You Should Know

2 Tháng Một, 2023
Top 10 CRM Software For Construction 
Tech

Top 10 CRM Software For Construction Enterprises All The Time

31 Tháng Mười Hai, 2022
What Is IBM Software
Software

What Is IBM Software? 4 Business Segments at IBM You Should Know

26 Tháng Mười Hai, 2022
W3Schools

Ads

Contact: [email protected]

DMCA.com Protection Status

Categories

  • Android
  • Cạm bẫy tâm lí
  • Chưa được phân loại
  • Đồ họa
  • Đời sống
  • Gen Z
  • Health
  • iOS
  • Kĩ năng mềm
  • News
  • Nhà mạng
  • Phần mềm
  • Phần mềm đồ họa
  • Review sách
  • Software
  • Tech
  • Thiết kế ảnh
  • Thiết kế video
  • Thủ thuật
  • Travel
  • Văn hóa Nam Bộ
  • Văn học
  • Window

Browse by Tag

ai là triệu phú android Apple browser Bullet Journal bản thân chai pin Chỉnh ảnh data domain download fshare game game show giả lập màu hosting IKEA ios khuyến mãi kinh doanh kiến thức kiểm tra pin messenger miễn phí mua sắm Máy ảnh mạng network nghệ thuật ngôn ngữ nhà Trần pin laptop quảng cáo tiếng anh trạng thái Trần Thủ Độ tên miền tắt hoạt động từ vựng video viettel window 10 word zalo Đơn giản

Recent News

How to get travel insurance

Guide on how to get travel insurance with 4 options

24 Tháng Một, 2023
Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

8 Tháng Một, 2023

Trang tin nóng hổi - vừa thổi vừa xem

No Result
View All Result
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z

Trang tin nóng hổi - vừa thổi vừa xem