The flaw, identified as CVE-2025-27915, is a stored cross-site scripting (XSS) vulnerability that attackers leveraged by sending weaponized iCalendar (.ICS) files to steal sensitive data from victims’ email accounts.
The attacks were first identified by StrikeReady, which began monitoring for unusually large iCalendar files that contained JavaScript.
One notable attack targeted Brazil’s military, where an attacker, using an IP address of 193.29.58.37, spoofed the Libyan Navy’s Office of Protocol to deliver the then-unknown exploit.
The core of the issue lies within Zimbra’s Classic Web Client, which failed to properly sanitize HTML content within iCalendar files. This allowed threat actors to embed malicious JavaScript inside a .ICS attachment.
When a user opened an email containing the malicious calendar entry, the script would execute within the user’s active session.
This XSS vulnerability, often considered less severe than remote code execution (RCE) flaws, proved highly effective.
It enabled attackers to run arbitrary code to perform unauthorized actions, including data exfiltration and session hijacking, without the user’s knowledge.
Zimbra addressed the vulnerability on January 27, 2025, by releasing patches (versions 9.0.0 P44, 10.0.13, and 10.1.5), though evidence shows the exploit was used before the fix was available.
The JavaScript payload delivered through the exploit is a sophisticated data stealer designed specifically for Zimbra webmail. Its capabilities include:
While direct attribution remains unconfirmed, researchers note the tactics are similar to those used by a prolific Russian-linked threat actor and the group UNC1151, which has been linked to the Belarusian government.
This incident underscores the significant threat posed by XSS vulnerabilities in enterprise environments and the importance of applying security patches promptly.
Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.
The post Hackers Exploit Zimbra Vulnerability as 0-Day with Weaponized iCalendar Files appeared first on Cyber Security News.
WASHINGTON (AP) — President Donald Trump made new threats to escalate strikes in Iran on…
EASTHAMPTON — In an effort to create a clearer and more cohesive downtown, the city…
SHUTESBURY — Shutesbury officials are continuing to take corrective action following the recent release of…
AMHERST — After breakfast each morning, Amherst Regional High School sophomore Ra-Star Ferreira rode on…
DEERFIELD — With a tough budget year ahead, Deerfield officials are discussing the need for…
SUNDERLAND — Discussion on the proposal for a 9,100-square-foot Dollar General on the corner of…
This website uses cookies.