EXPOSURES › CVE-2022-27925
CVE-2022-27925
CRITICAL ⌖ ON CISA KEV · EXPLOITEDAn unpatched arbitrary file upload flaw in Zimbra's mboximport functionality allowed authenticated attackers to execute remote code, which was chained with an unauthenticated RCE to compromise systems.
Synacor's Zimbra Collaboration Suite suffered from a critical unpatched vulnerability in its mboximport feature that permitted authenticated attackers to upload arbitrary files for remote code execution. This flaw was actively exploited in ransomware campaigns and chained with another unpatched RCE vulnerability, demonstrating a chronic failure in vulnerability management. DIB organizations must ensure their email and collaboration platforms are patched against known RCE flaws and monitored for active exploitation in the wild.
Shame score — The vendor failed to patch critical RCE vulnerabilities for years, allowing them to be actively exploited in ransomware attacks, which is a severe and avoidable negligence.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Synacor Zimbra Collaboration Suite (ZCS) contains flaw in the mboximport functionality, allowing an authenticated attacker to upload arbitrary files to perform remote code execution. This vulnerability was chained with CVE-2022-37042 which allows for unauthenticated remote code execution.