HomeSecurityZimbra zero-day vulnerability allows email theft

Zimbra zero-day vulnerability allows email theft

Malicious actors appear to have discovered and are actively exploiting a zero-day vulnerability in Zimbra to launch attacks on European media and government organizations.

Zimbra

See also: Apple fixes zero-day bugs affecting iOS/macOS devices

Zimbra is an email platform that also includes instant messaging, contacts, video conferencing, file sharing, and cloud storage capabilities.

According to Zimbra, more than 200,000 businesses from over 140 countries use its software, including over 1,000 government and financial organizations.

"This exploit does not have any patch available, nor has it been assigned a CVE, making it a zero-day vulnerability," the researchers said.

“Volexity can confirm and has tested that the latest versions of Zimbra—8.8.15 P29 & P30—remain vulnerable. Testing of version 9.0.0 indicates that it is likely not affected.“

Volexity says that so far, it has only observed a single malicious actor known as TEMP_Heretic, likely from China, that exploits the zero-day in spear-phishing to steal emails.

See also: Windows: Zero-day “RemotePotato0” receives unofficial update

However, the vulnerability could also allow attackers to perform other malicious actions “within the context of the user’s Zimbra email session,” such as:

  • Export cookies to allow permanent access to a mailbox
  • Sending phishing messages to the user's contacts
  • Prompting to download malware from seemingly trustworthy websites
zero day

Since the exploit was launched in December, Volexity has seen TEMP_Heretic checking for live email addresses, using email IDs with embedded remote images.

In the next stage of the attack, malicious users sent spear-phishing emails with malicious links and various subjects (e.g., interview requests, invitations to charity auctions, and holiday wishes) in multiple waves between mid-December 2021.

“By clicking on the malicious link, the attacker’s infrastructure will attempt a redirect to a page on the targeted organization’s Zimbra email server, with a specific URI format which—if the user is logged in—exploits a vulnerability that allows arbitrary JavaScript to be loaded within a logged-in Zimbra session,” the researchers added.

The malicious code allows attackers to sneak through emails into victims' mailboxes and infiltrate email content and attachments on servers controlled by the attackers.

See also: Diavol ransomware spreads via email and steals money

Volexity recommends taking the following measures to block attacks that exploit this vulnerability:

  • All indications here should be blocked at the mail gateway and network level.
  • Zimbra users should analyze referral data for suspicious access and referrals.
  • Zimbra users should consider upgrading to version 9.0.0, as there is currently no secure version of 8.8.15.
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS