The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →In June 2023, Google’s Threat Analysis Group (TAG) discovered attackers exploiting a previously unknown vulnerability in Zimbra Collaboration, a web-based email and collaboration platform. The reflected cross-site scripting flaw, later assigned CVE-2023-37580, was used in four campaigns targeting government organizations in Greece, Moldova, Tunisia, Vietnam, and Pakistan. The campaigns had different operators and goals: email and attachment theft, credential phishing, and theft of a Zimbra authentication token.
This is a historical account of activity Google observed and reported on November 16, 2023; it does not establish the full extent of attacks or the current security status of any Zimbra installation. Google TAG’s report describes how the activity unfolded and why applying the official patch mattered.
What was CVE-2023-37580, and how did the attack work?
CVE-2023-37580 was a reflected cross-site scripting (XSS) vulnerability in Zimbra Collaboration. In an XSS attack, a malicious script is made to run in a user’s browser in the context of a trusted website. Google said the flaw allowed a URL parameter to be inserted into a webpage without adequate escaping. Zimbra’s fix escaped the contents of the st parameter before using it as an HTML object value.
The vulnerability did not, on its own, steal an organization’s mail. In the campaigns Google described, attackers sent specially crafted links, and the results depended on the campaign’s script and the target’s circumstances. For example, the Greece attack could load its email-stealing framework if a target clicked the link while logged into Zimbra.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
Which countries were targeted, and what did attackers do?
Google described four campaigns. The activity differed by target, timing, attribution, and intended outcome; the report does not attribute every campaign to the same group.
| Target | Timing reported by Google | Attribution | Observed approach and objective |
|---|---|---|---|
| Greece | June 29, 2023 | Not specified for this campaign in the report | An exploit link could load a framework previously documented by Volexity. It could steal emails and attachments and create an automatic forwarding rule to an attacker-controlled address. |
| Moldova and Tunisia | Activity began July 11, 2023 | Winter Vivern (UNC4907) | Exploit URLs targeted government organizations and included unique official email addresses. Google did not describe this campaign’s objective as the same mail-stealing framework observed in Greece. |
| Vietnam | Observed around July 20, 2023 | Unidentified actor | An exploit URL displayed a webmail credential-phishing page. Stolen credentials were sent to a URL on an official government domain that Google assessed was likely compromised. |
| Pakistan | Campaign began August 25, 2023, after the official patch | Not specified for this campaign in the report | The campaign used the vulnerability to steal a Zimbra authentication token from a target that remained vulnerable. |
The Moldova and Tunisia activity is the campaign Google explicitly attributed to Winter Vivern. The report identifies an unidentified actor in the Vietnam campaign and does not provide attribution for every other campaign, so it would be inaccurate to describe all four as the work of one group.
Rank #2
When did Zimbra release the hotfix, advisory, and official patch?
The dates are distinct: a hotfix appeared on public GitHub first, Zimbra then issued an advisory with remediation guidance, and the official patch followed. Google reported that three threat groups exploited the issue before that official patch and that it found a fourth campaign afterward.
| Date | Event | Why it matters |
|---|---|---|
| June 2023 | Google TAG discovered in-the-wild exploitation of the zero-day. | The vulnerability was already being used before it had an official CVE patch. |
| July 5, 2023 | Zimbra pushed a hotfix to public GitHub. | A public hotfix did not mean every Zimbra installation had been updated. |
| July 13, 2023 | Zimbra published an initial advisory with remediation guidance. | The advisory provided remediation context ahead of the official patch. |
| July 25, 2023 | Zimbra patched the issue as CVE-2023-37580. | Google later observed the Pakistan campaign against a target that remained vulnerable. |
The post-patch Pakistan activity was exploitation of a system that was still unpatched or otherwise vulnerable; it was not a new zero-day. Google’s report illustrates why organizations need to deploy fixes, rather than treating a public hotfix, advisory, or patch release as proof that their own systems are protected.
Quick Recap
Best Value
Rank #4
Rank #3
What should Zimbra administrators take from the report?
- Apply vendor security updates promptly. Google TAG urged users and organizations to keep software fully up to date and apply security updates as soon as they become available.
- Track remediation guidance as well as release announcements. The hotfix, advisory, and official patch arrived on separate dates, and exploitation continued during that sequence.
- Confirm deployment on the systems that matter. A fix being publicly available does not establish that a particular server received it.
- Use current vendor guidance for present-day decisions. Google’s November 2023 account describes historical activity; it does not establish which Zimbra versions remain vulnerable today.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

