peter bassill · operator
$ cve CVE-2022-41352 JSON

CVE-2022-41352 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 95.5% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-11-10.

Description

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red Hat installation after RHEL 6 (or CentOS 6). Once pax is installed, amavis automatically prefers it over cpio.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS95.48% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-22
On CISA KEVyes — remediate by 2022-11-10
Public exploitnone known
Published2022-09-26
Last modified2026-09-10

CISA KEV

NameSynacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability
Added2022-10-20
Due2022-11-10
Vendor / productSynacor / Zimbra Collaboration Suite (ZCS)
Ransomware useknown

Affected (1)

VendorProduct
synacorzimbra collaboration suite

References

→ the Explorer  ·  watch your stack  ·  NVD