{"id":9909,"date":"2022-03-01T04:07:00","date_gmt":"2022-03-01T06:07:00","guid":{"rendered":"https:\/\/teknomers.com\/fr\/cisa-ajoute-le-bogue-zimbra-recemment-divulgue-a-son-catalogue-de-vulnerabilites-exploitees\/"},"modified":"2022-03-01T04:07:17","modified_gmt":"2022-03-01T06:07:17","slug":"cisa-ajoute-le-bogue-zimbra-recemment-divulgue-a-son-catalogue-de-vulnerabilites-exploitees","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/cisa-ajoute-le-bogue-zimbra-recemment-divulgue-a-son-catalogue-de-vulnerabilites-exploitees\/","title":{"rendered":"CISA ajoute le bogue Zimbra r\u00e9cemment divulgu\u00e9 \u00e0 son catalogue de vuln\u00e9rabilit\u00e9s exploit\u00e9es"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both\"><\/div>\n<p>L&#8217;Agence am\u00e9ricaine pour la cybers\u00e9curit\u00e9 et la s\u00e9curit\u00e9 des infrastructures (CISA) <a rel=\"nofollow noopener\" href=\"https:\/\/www.cisa.gov\/uscert\/ncas\/current-activity\/2022\/02\/25\/cisa-adds-four-known-exploited-vulnerabilities-catalog\" target=\"_blank\">\u00e9tendu<\/a> son catalogue de vuln\u00e9rabilit\u00e9s exploit\u00e9es connues pour inclure une faille zero-day r\u00e9cemment r\u00e9v\u00e9l\u00e9e dans la plate-forme de messagerie Zimbra citant des preuves d&#8217;exploitation active dans la nature.<\/p>\n<p>Suivi comme <a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-24682\" target=\"_blank\">CVE-2022-24682<\/a> (score CVSS\u00a0: 6,1), le probl\u00e8me concerne une vuln\u00e9rabilit\u00e9 de script intersite (XSS) dans la fonctionnalit\u00e9 de calendrier de Zimbra Collaboration Suite qui pourrait \u00eatre exploit\u00e9e par un attaquant pour inciter les utilisateurs \u00e0 t\u00e9l\u00e9charger du code JavaScript arbitraire simplement en cliquant sur un lien pour exploiter les URL. dans les messages de phishing.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/backhub-dm2\" target=\"_blank\" title=\"Automatic GitHub Backups\"><img loading=\"lazy\" decoding=\"async\" alt=\"Sauvegardes GitHub automatiques\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/02\/Avertissement-\u2014-Deadbolt-Ransomware-ciblant-les-peripheriques-NAS-ASUSTOR.png\" width=\"300\" height=\"250\" \/><\/a><\/div>\n<p>Le catalogue des vuln\u00e9rabilit\u00e9s exploit\u00e9es connues est un <a rel=\"nofollow noopener\" href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\">d\u00e9p\u00f4t<\/a> des failles de s\u00e9curit\u00e9 qui ont \u00e9t\u00e9 vues abus\u00e9es par les acteurs de la menace lors d&#8217;attaques et qui doivent \u00eatre corrig\u00e9es par les agences du pouvoir ex\u00e9cutif civil f\u00e9d\u00e9ral (FCEB).<\/p>\n<p>La vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 r\u00e9v\u00e9l\u00e9e le 3 f\u00e9vrier 2022, lorsque la soci\u00e9t\u00e9 de cybers\u00e9curit\u00e9 Volexity a identifi\u00e9 une s\u00e9rie de campagnes de harponnage cibl\u00e9es visant les gouvernements europ\u00e9ens et les entit\u00e9s m\u00e9diatiques qui ont exploit\u00e9 la faille susmentionn\u00e9e pour obtenir un acc\u00e8s non autoris\u00e9 aux bo\u00eetes aux lettres des victimes et planter des logiciels malveillants.<\/p>\n<p>Volexity suit l&#8217;acteur sous le nom de &#8220;TEMP_HERETIC&#8221;, les attaques affectant l&#8217;\u00e9dition open-source de Zimbra ex\u00e9cutant la version 8.8.15.  Zimbra a depuis <a rel=\"nofollow noopener\" href=\"https:\/\/blog.zimbra.com\/2022\/02\/hotfix-available-5-feb-for-zero-day-exploit-vulnerability-in-zimbra-8-8-15\/\" target=\"_blank\">pouss\u00e9<\/a> un hotfix (version <a rel=\"nofollow noopener\" href=\"https:\/\/wiki.zimbra.com\/wiki\/Zimbra_Releases\/8.8.15\/P30\" target=\"_blank\">8.8.15 P30<\/a>) pour corriger le d\u00e9faut.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/cs-jan-webinar-inside\" target=\"_blank\" title=\"Prevent Data Breaches\"><img loading=\"lazy\" decoding=\"async\" alt=\"Emp\u00eacher les violations de donn\u00e9es\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/02\/1645701002_140_Dridex-Malware-Deploiement-Entropy-Ransomware-sur-des-ordinateurs-pirates.png\" width=\"728\" height=\"90\" \/><\/a><\/div>\n<p>En raison de l&#8217;impact potentiel de cette vuln\u00e9rabilit\u00e9, la CISA a donn\u00e9 aux agences f\u00e9d\u00e9rales jusqu&#8217;au 11 mars 2022 pour appliquer les mises \u00e0 jour de s\u00e9curit\u00e9.  En plus de CVE-2022-24682, CISA a \u00e9galement ajout\u00e9 les trois vuln\u00e9rabilit\u00e9s suivantes au catalogue &#8211;<\/p>\n<ul>\n<li><a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-8570\" target=\"_blank\"><strong>CVE-2017-8570<\/strong><\/a>  (Score CVSS : 7,8) \u2013 Vuln\u00e9rabilit\u00e9 d&#8217;ex\u00e9cution de code \u00e0 distance dans Microsoft Office<\/li>\n<li><a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-0222\" target=\"_blank\"><strong>CVE-2017-0222<\/strong><\/a>  (Score CVSS : 7,5) \u2013 Vuln\u00e9rabilit\u00e9 de corruption de la m\u00e9moire de Microsoft Internet Explorer<\/li>\n<li><a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2014-6352\" target=\"_blank\"><strong>CVE-2014-6352<\/strong><\/a>  (Score CVSS : N\/A) \u2013 Vuln\u00e9rabilit\u00e9 d&#8217;injection de code Microsoft Windows<\/li>\n<\/ul>\n<p><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2022\/02\/cisa-adds-recently-disclosed-zimbra-bug.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>L&#8217;Agence am\u00e9ricaine pour la cybers\u00e9curit\u00e9 et la s\u00e9curit\u00e9 des infrastructures (CISA) \u00e9tendu son catalogue de vuln\u00e9rabilit\u00e9s exploit\u00e9es connues pour inclure une faille zero-day r\u00e9cemment r\u00e9v\u00e9l\u00e9e dans la plate-forme de messagerie Zimbra citant des preuves d&#8217;exploitation active dans la nature. Suivi comme CVE-2022-24682 (score CVSS\u00a0: 6,1), le probl\u00e8me concerne une vuln\u00e9rabilit\u00e9 de script intersite (XSS) dans [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":9910,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[12361,6813,12364,4805,4168,4158,4165,4161,6905,4808,4157,4159,4171,4170,4167,4160,4163,4162,12363,4172,4169,167,4166,4164,12365,12362],"class_list":["post-9909","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-ajoute","tag-bogue","tag-catalogue","tag-cisa","tag-comment-pirater","tag-cyber-actualites","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-divulgue","tag-exploitees","tag-lactualite-de-la-cybersecurite","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-la-securite-des-informations","tag-logiciel-malveillant-de-ransomware","tag-mises-a-jour-de-la-cybersecurite","tag-nouvelles-de-piratage","tag-nouvelles-de-pirates","tag-recemment","tag-securite-informatique","tag-securite-internet","tag-son","tag-violation-de-donnees","tag-vulnerabilite-logicielle","tag-vulnerabilites","tag-zimbra"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/9909","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=9909"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/9909\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/9910"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=9909"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=9909"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=9909"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}