SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2022-27925

Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability

KEVHIGH 7.2EPSS 98.7%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 1 September 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.

CVSS 3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
98.68% probability · 100th percentile
CISA KEV
Listed 11 August 2022 · due 1 September 2022 · used in ransomware campaigns
Weakness
CWE-22
Affected
synacor/zimbra collaboration suite
Source
cve@mitre.org

CISA notes

Apply updates per vendor instructions. https://blog.zimbra.com/2022/08/authentication-bypass-in-mailboximportservlet-vulnerability/; https://nvd.nist.gov/vuln/detail/CVE-2022-27925

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.