CVE-2022-37042
synacor zimbra collaboration suite
Published 12 Aug 2022 · updated 4 Aug 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 11 Aug 2022, with a remediation deadline of 1 Sept 2022 for US federal agencies. It has been used in ransomware campaigns.
Required action: Apply updates per vendor instructions.
Description
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925.
References
- packetstormsecurity.com/files/168146/Zimbra-Zip-Path-Traversal.html · Exploit, Third Party Advisory, VDB Entry
- wiki.zimbra.com/wiki/Security_Center · Patch, Vendor Advisory
- wiki.zimbra.com/wiki/Zimbra_Security_Advisories · Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-37042 · US Government Resource