CVE-2022-37042 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 91.9% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-09-01.
Description
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 91.89% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | yes — remediate by 2022-09-01 |
| Public exploit | none known |
| Published | 2022-08-12 |
| Last modified | 2026-08-04 |
CISA KEV
| Name | Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass Vulnerability |
|---|---|
| Added | 2022-08-11 |
| Due | 2022-09-01 |
| Vendor / product | Synacor / Zimbra Collaboration Suite (ZCS) |
| Ransomware use | known |
Affected (1)
| Vendor | Product |
|---|---|
| synacor | zimbra collaboration suite |
References
- http://packetstormsecurity.com/files/168146/Zimbra-Zip-Path-Traversal.html
- https://wiki.zimbra.com/wiki/Security_Center
- https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
- http://packetstormsecurity.com/files/168146/Zimbra-Zip-Path-Traversal.html
- https://wiki.zimbra.com/wiki/Security_Center
- https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-37042
→ the Explorer · watch your stack · NVD