CVE-2022-27924
Synacor Zimbra Collaboration Suite (ZCS) Command Injection Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 25 August 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These memcache commands becomes unescaped, causing an overwrite of arbitrary cached entries.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 85.40% probability · 100th percentile
- CISA KEV
- Listed 4 August 2022 · due 25 August 2022 · used in ransomware campaigns
- Weakness
- CWE-74
- Affected
- synacor/zimbra collaboration suite
- Source
- cve@mitre.org
CISA notes
Apply updates per vendor instructions. https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P24.1#Security_Fixes; https://nvd.nist.gov/vuln/detail/CVE-2022-27924
References
- https://wiki.zimbra.com/wiki/Security_CenterVendor Advisory
- https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P24Release Notes, Vendor Advisory
- https://wiki.zimbra.com/wiki/Zimbra_Security_AdvisoriesVendor Advisory
- https://wiki.zimbra.com/wiki/Security_CenterVendor Advisory
- https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P24Release Notes, Vendor Advisory
- https://wiki.zimbra.com/wiki/Zimbra_Security_AdvisoriesVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-27924US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.