Microsoft said it detected two distinct scanning tools probing the internet for vulnerable Zimbra endpoints between July 28 and August 7. The attackers first validated their exploits by sending HTTP requests, DNS, ICMP and out-of-band identity checks to domains hosted on public services, confirming they could execute commands on vulnerable servers without actually compromising them. They then used the command injection capability to install malicious payloads.
The vulnerability allows remote attackers to issue operating system commands without authentication. Microsoft's warning follows a report from the Shadowserver Foundation, which said last week that its scans found 274 separate instances of the Zimbra Collaboration Suite had been compromised. The number of servers running the software has fluctuated since the patch was released, from about 19,000 instances in the week after the patch to roughly 12,000 in subsequent weeks. Shadowserver is currently tracking about 10,000 instances.
Organizations running Zimbra Collaboration Suite are urged to apply the patch immediately and check for signs of compromise, particularly on internet-facing mail servers.