peter bassill · operator
$ cve CVE-2022-37042 JSON

CVE-2022-37042 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 91.9% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-09-01.

Description

Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS91.89% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-22
On CISA KEVyes — remediate by 2022-09-01
Public exploitnone known
Published2022-08-12
Last modified2026-08-04

CISA KEV

NameSynacor Zimbra Collaboration Suite (ZCS) Authentication Bypass Vulnerability
Added2022-08-11
Due2022-09-01
Vendor / productSynacor / Zimbra Collaboration Suite (ZCS)
Ransomware useknown

Affected (1)

VendorProduct
synacorzimbra collaboration suite

References

→ the Explorer  ·  watch your stack  ·  NVD