CVE-2022-27925
unknown
KEV
CVSS v3
—
CVSS v2
—
VIR risk
1.5
Description
Synacor Zimbra Collaboration Suite (ZCS) contains flaw in the mboximport functionality, allowing an authenticated attacker to upload arbitrary files to perform remote code execution. This vulnerability was chained with CVE-2022-37042 which allows for unauthenticated remote code execution.
CISA KEV
- Vendor
- Synacor
- Product
- Zimbra Collaboration Suite (ZCS)
- Due date
- 2022-09-01
Predictions
Exploit likelihood
99%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cisa-kev — https://blog.zimbra.com/2022/08/authentication-bypass-in-mailboximportservlet-vulnerability/; https://nvd.nist.gov/vuln/detail/CVE-2022-27925
Exploits
References
Verify integrity in audit chain (admin only). AS-IS.