Skip to content
COOEY

EXPOSURES › CVE-2022-27925

CVE-2022-27925

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-08-11 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-27925 ↗
⚡ RCE ◐ ZERO-DAY ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildunpatched

An unpatched arbitrary file upload flaw in Zimbra's mboximport functionality allowed authenticated attackers to execute remote code, which was chained with an unauthenticated RCE to compromise systems.

Synacor's Zimbra Collaboration Suite suffered from a critical unpatched vulnerability in its mboximport feature that permitted authenticated attackers to upload arbitrary files for remote code execution. This flaw was actively exploited in ransomware campaigns and chained with another unpatched RCE vulnerability, demonstrating a chronic failure in vulnerability management. DIB organizations must ensure their email and collaboration platforms are patched against known RCE flaws and monitored for active exploitation in the wild.

Shame score — The vendor failed to patch critical RCE vulnerabilities for years, allowing them to be actively exploited in ransomware attacks, which is a severe and avoidable negligence.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Synacor Zimbra Collaboration Suite (ZCS) contains flaw in the mboximport functionality, allowing an authenticated attacker to upload arbitrary files to perform remote code execution. This vulnerability was chained with CVE-2022-37042 which allows for unauthenticated remote code execution.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.