EXPOSURES › CVE-2022-37042
CVE-2022-37042
CRITICAL ⌖ ON CISA KEV · EXPLOITEDSynacor's Zimbra Collaboration Suite suffered an authentication bypass vulnerability chained with an unpatched RCE flaw, enabling ransomware actors to execute arbitrary code without authentication.
The MailboxImportServlet authentication bypass was chained with CVE-2022-27925, allowing unauthenticated remote code execution. DIB organizations must ensure Zimbra is patched and monitored, as Synacor's chronic failure to address critical flaws leaves systems vulnerable to ransomware and data breaches. Immediate patching and continuous vulnerability scanning are required to mitigate this exposure.
Shame score — Synacor repeatedly failed to patch critical RCE and authentication bypass flaws, allowing active exploitation by ransomware campaigns over multiple years.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Synacor Zimbra Collaboration Suite (ZCS) contains an authentication bypass vulnerability in MailboxImportServlet. This vulnerability was chained with CVE-2022-27925 which allows for unauthenticated remote code execution.