CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2022-37042

CVSS 9.8v3.1pub. 2022-08-12upd. 2026-08-04

Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Synacor Zimbra Collaboration Suite

    APP
    Synacor
    8.8.159.0.0

CISA KEV — detailsi

Vendori
Synacor
Producti
Zimbra Collaboration Suite (ZCS)
Added to KEVi
August 11, 2022
Remediation deadline (US Federal)i
September 1, 2022(overdue)
Ransomwarei
Active ransomware campaigns exploit this vulnerability
Required action (CISA)i

Apply updates per vendor instructions.

CISA descriptioni

Synacor Zimbra Collaboration Suite (ZCS) contains an authentication bypass vulnerability in MailboxImportServlet. This vulnerability was chained with CVE-2022-27925 which allows for unauthenticated remote code execution.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
☠️WYKORZYSTYWANE W RANSOMWARECISA DEADLINE: 1 września 2022
Tags
RCEPath Traversal
CWE
References

Related vulnerabilities

CVE-2024-45519CRITICAL10.0⚠ KEVPL ✓same product

RCE w usłudze postjournal Zimbra Collaboration Suite — command injection bez uwierzytelnienia

CVE-2023-34192CRITICAL9.0⚠ KEVPL ✓same product

XSS umożliwiający RCE w Zimbra Collaboration Suite 8.8.15

CVE-2022-41352CRITICAL9.8⚠ KEVPL ✓same product

Zimbra Collaboration – path traversal przez cpio umożliwia przejęcie kont

CVE-2020-7796CRITICAL9.8⚠ KEVPL ✓same product

SSRF w Zimbra Collaboration Suite przez WebEx zimlet

CVE-2019-9670CRITICAL9.8⚠ KEVPL ✓same product

XXE w komponencie mailboxd Synacor Zimbra Collaboration Suite