The flaw, identified as CVE-2025-27915, is a stored cross-site scripting (XSS) vulnerability that attackers leveraged by sending weaponized iCalendar (.ICS) files to steal sensitive data from victims’ email accounts.
The attacks were first identified by StrikeReady, which began monitoring for unusually large iCalendar files that contained JavaScript.
One notable attack targeted Brazil’s military, where an attacker, using an IP address of 193.29.58.37, spoofed the Libyan Navy’s Office of Protocol to deliver the then-unknown exploit.
The core of the issue lies within Zimbra’s Classic Web Client, which failed to properly sanitize HTML content within iCalendar files. This allowed threat actors to embed malicious JavaScript inside a .ICS attachment.
When a user opened an email containing the malicious calendar entry, the script would execute within the user’s active session.
This XSS vulnerability, often considered less severe than remote code execution (RCE) flaws, proved highly effective.
It enabled attackers to run arbitrary code to perform unauthorized actions, including data exfiltration and session hijacking, without the user’s knowledge.
Zimbra addressed the vulnerability on January 27, 2025, by releasing patches (versions 9.0.0 P44, 10.0.13, and 10.1.5), though evidence shows the exploit was used before the fix was available.
The JavaScript payload delivered through the exploit is a sophisticated data stealer designed specifically for Zimbra webmail. Its capabilities include:
While direct attribution remains unconfirmed, researchers note the tactics are similar to those used by a prolific Russian-linked threat actor and the group UNC1151, which has been linked to the Belarusian government.
This incident underscores the significant threat posed by XSS vulnerabilities in enterprise environments and the importance of applying security patches promptly.
Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.
The post Hackers Exploit Zimbra Vulnerability as 0-Day with Weaponized iCalendar Files appeared first on Cyber Security News.
All of the Sage Spirits you get to accompany you on your journey in The…
Xbox is adding a new Gamerscore-tracking feature for your console, allowing you to show off…
HBO Max has released the debut trailer for Stuart Fails to Save the Universe, its…
SteelSeries' honeycombed Aerox 3 was one of the best gaming mice of 2022 – so…
Netflix’s new series, The Boroughs, follows a small group of aging residents in a seemingly…
Gong has announced a business update following the end of its most recent quarter. As…
This website uses cookies.