CVE-2022-24682
MEDIUM(6.1)KEV — Aktiv ausgenutztCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- CVSS 6.1 — Mittel
- EPSS 31%
- Im CISA KEV-Katalog (aktiv ausgenutzt)
CISA KEV
Bestätigt ausgenutzt
EPSS-Score
30.9%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
6.1
Technische Schwere
SecBoard-Einordnung
CVE-2022-24682 betrifft die Kalenderfunktion der Zimbra Collaboration Suite. Es handelt sich um eine Cross-Site Scripting (XSS)-Schwachstelle, die es einem Angreifer ermöglicht, bösartigen HTML-Code mit ausführbarem JavaScript in Elementattributen zu platzieren. Dieser Code wird nicht korrekt maskiert, was zur Injektion von beliebigem Markup in das Dokument führt und potenziell die Ausführung von Skripten im Browser des Benutzers ermöglicht.
Die Schwachstelle wird als mittelschwer eingestuft (CVSS 6.1), hat jedoch eine erhöhte Relevanz, da sie aktiv ausgenutzt wird (CISA KEV) und eine Exploit-Wahrscheinlichkeit von 31% (EPSS) aufweist. Die Ausnutzung wurde bereits im Dezember 2021 in freier Wildbahn beobachtet, was auf eine anhaltende Bedrohung hindeutet.
Security-Teams sollten die Zimbra Collaboration Suite umgehend auf die Version 8.8.15 Patch 30 (Update 1) oder höher aktualisieren, um diese Schwachstelle zu beheben. Aufgrund der aktiven Ausnutzung ist eine schnelle Priorisierung und Implementierung des Patches dringend erforderlich, um das Risiko für die Organisation zu minimieren.
KI-gestützte Einordnung auf Basis der NVD-Daten.
Beschreibung
An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document.
Referenzen
- https://blog.zimbra.com/2022/02/hotfix-available-5-feb-for-zero-day-exploit-vuln...
- https://wiki.zimbra.com/wiki/Security_Center
- https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P30
- https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
- https://www.volexity.com/blog/2022/02/03/operation-emailthief-active-exploitatio...
- https://blog.zimbra.com/2022/02/hotfix-available-5-feb-for-zero-day-exploit-vuln...
- https://wiki.zimbra.com/wiki/Security_Center
- https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P30
- https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
- https://www.volexity.com/blog/2022/02/03/operation-emailthief-active-exploitatio...