CVE-2022-24682
Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 11 March 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 30.93% probability · 98th percentile
- CISA KEV
- Listed 25 February 2022 · due 11 March 2022 · used in ransomware campaigns
- Weakness
- CWE-116
- Affected
- synacor/zimbra collaboration suite
- Source
- cve@mitre.org
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2022-24682
References
- https://blog.zimbra.com/2022/02/hotfix-available-5-feb-for-zero-day-exploit-vulnerability-in-zimbra-8-8-15/Vendor Advisory
- https://wiki.zimbra.com/wiki/Security_CenterVendor Advisory
- https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P30Release Notes, Vendor Advisory
- https://wiki.zimbra.com/wiki/Zimbra_Security_AdvisoriesVendor Advisory
- https://www.volexity.com/blog/2022/02/03/operation-emailthief-active-exploitation-of-zero-day-xss-vulnerability-in-zimbra/Exploit, Third Party Advisory
- https://blog.zimbra.com/2022/02/hotfix-available-5-feb-for-zero-day-exploit-vulnerability-in-zimbra-8-8-15/Vendor Advisory
- https://wiki.zimbra.com/wiki/Security_CenterVendor Advisory
- https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P30Release Notes, Vendor Advisory
- https://wiki.zimbra.com/wiki/Zimbra_Security_AdvisoriesVendor Advisory
- https://www.volexity.com/blog/2022/02/03/operation-emailthief-active-exploitation-of-zero-day-xss-vulnerability-in-zimbra/Exploit, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-24682US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.