Kaspersky Lab¤Ï10·î13Æü(Êƹñ»þ´Ö)¡¢¡ÖOngoing exploitation of CVE-2022-41352¡ÊZimbra 0-day¡Ë¡Ã Securelist¡×¤Ë¤ª¤¤¤Æ¡¢¡ÖZimbra Collaboration Suite¡ÊZCS¡Ë¡×¤Ë¸ºß¤·¤¿¥¼¥í¥Ç¥£ÀȼåÀ­¤¬Ì¤ÃΤλý³ŪɸŪ·¿¹¶·â(APT: Advanced Persistent Threat)¥°¥ë¡¼¥×¤Ë°­ÍѤµ¤ì¤Æ¤¤¤ë¤ÈÅÁ¤¨¤¿¡£Kaspersky Lab¤ÎÄ´ºº¤Ë¤è¤ê¡¢Ì¤ÃΤλý³ŪɸŪ·¿¹¶·â¥°¥ë¡¼¥×¤¬¤³¤ÎÀȼåÀ­¤òÀѶËŪ¤Ë°­ÍѤ·¡¢Ãæ±û¥¢¥¸¥¢¤Ë¤¢¤ëÀȼå¤Ê¥µ¡¼¥Ð¤òÁÈ¿¥Åª¤Ë´¶À÷¤µ¤»¤Æ¤¤¤ë¤³¤È¤¬ÌÀ¤é¤«¤È¤Ê¤Ã¤¿¡£

Ongoing exploitation of CVE-2022-41352¡ÊZimbra 0-day¡Ë¡Ã Securelist

ÀѶËŪ¤Ë°­ÍѤµ¤ì¤Æ¤¤¤ë¤³¤ÎÀȼåÀ­¤Ï¡ÖCVE-2022-41352¡×¤È¤·¤ÆÆÃÄꤵ¤ì¤Æ¤ª¤ê¡¢¿¼¹ïÅÙ¤¬CVSSv3¥¹¥³¥¢ÃÍ9.8¤ÇCritical(¶ÛµÞ)¤È°ÌÃ֤Ť±¤é¤ì¤Æ¤¤¤ë¡£¤³¤ÎÀȼåÀ­¤Ï¡ÖAmavis¡×¤È¸Æ¤Ð¤ì¤ëZimbra¤Î¥³¥ó¥Ý¡¼¥Í¥ó¥È¡¢¤è¤ê¶ñÂÎŪ¤Ë¤Ï¥¢¡¼¥«¥¤¥Ö¤òÃê½Ð¤¹¤ë¤¿¤á¤Ë»ÈÍѤµ¤ì¤ëcpio¥æ¡¼¥Æ¥£¥ê¥Æ¥£¤ÎÀȼåÀ­¡ÖCVE-2015-1197¡×¤¬±Æ¶Á¤·¤Æ¤¤¤ë¡£

¤³¤ÎÀȼåÀ­¤Î¥¨¥¯¥¹¥×¥í¥¤¥È¥·¥Ê¥ê¥ª¤Ï¼¡¤Î¼ê½ç¤Ç¼Â¹Ô¤µ¤ì¤ë¡£

¹¶·â¼Ô¤¬°­°Õ¤Î¤¢¤ëtar¥¢¡¼¥«¥¤¥Ö¤òźÉÕ¤·¤¿ÅŻҥ᡼¥ë¤òÁ÷¿®

Zimbra¤¬ÅŻҥ᡼¥ë¤ò¼õ¿®¤¹¤ë¤È¥¹¥Ñ¥à¤ª¤è¤Ó¥Þ¥ë¥¦¥§¥¢¸¡ºº¤Î¤¿¤á¤ËAmavis¤ËÁ÷¿®

Amavis¤¬ÅŻҥ᡼¥ë¤ÎźÉÕ¥Õ¥¡¥¤¥ë¤òʬÀÏ¡£cpio¤¬µ¯Æ°¤µ¤ì¤¿»þ¤Ë¡ÖCVE-2015-1197¡×¤¬¥È¥ê¥¬¡¼¤µ¤ì¤ë

Ãê½ÐÃæ¡¢Web¥á¡¼¥ë¥³¥ó¥Ý¡¼¥Í¥ó¥È¤¬»ÈÍѤ¹¤ë¥Ñ¥Ö¥ê¥Ã¥¯¥Ç¥£¥ì¥¯¥È¥ê¤Î¤Ò¤È¤Ä¤ËSP Web¥·¥§¥ë¤¬Å¸³«¤µ¤ì¤ë¡£¹¶·â¼Ô¤ÏWeb¥·¥§¥ë¤Ë¥Ö¥é¥¦¥º¤·¤Æ¡¢Èï³²¼Ô¥Þ¥·¥ó¾å¤ÇǤ°Õ¤Î¥³¥Þ¥ó¥É¤Î¼Â¹Ô¤ò³«»Ï¤¹¤ë¤³¤È¤¬²Äǽ¤È¤Ê¤ë

in the context of CVE-2022-41352, the exploitation scenario unfolds¡Ã Securelist

Zimbra¤Ï¡¢¤³¤ÎÀȼåÀ­¤ËÂбþ¤·¤¿¥»¥­¥å¥ê¥Æ¥£¥Ñ¥Ã¥Á¤òŬÍѤ·¤¿¡ÖZimbra Collaboration Suite 9.0.0 P27¡×¤ò2022ǯ10·î10Æü¤Ë¸ø³«¤·¤Æ¤¤¤ë¡£Zimbra Collaboration Suite¤òÍøÍѤ·¤Æ¤¤¤ë¥æ¡¼¥¶¤ÏÆâÍƤò³Îǧ¤¹¤ë¤È¤È¤â¤Ë¡¢ÌäÂ꤬½¤Àµ¤µ¤ì¤¿ºÇ¿·ÈǤإ¢¥Ã¥×¥Ç¡¼¥È¤¹¤ë¤³¤È¤¬¿ä¾©¤µ¤ì¤Æ¤¤¤ë¡£