CVE-2022-37042
Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass Vulnerability
CVSS
9.8
Critical
EPSS
91.9%
p100
KEV
YES
Aug 11, 2022
Exploit Today
80
0-100
Published: Aug 12, 2022 · Last modified: Aug 4, 2026 · CWE-22
Product
Synacor / Zimbra Collaboration Suite (ZCS)
Vulnerability
Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass Vulnerability
Added to KEV
Aug 11, 2022
Remediate by
Sep 1, 2022
Known ransomware use
Yes
Summary description
Synacor Zimbra Collaboration Suite (ZCS) contains an authentication bypass vulnerability in MailboxImportServlet. This vulnerability was chained with CVE-2022-27925 which allows for unauthenticated remote code execution.
Required action
Apply updates per vendor instructions.
Notes
https://blog.zimbra.com/2022/08/authentication-bypass-in-mailboximportservlet-vulnerability/; https://nvd.nist.gov/vuln/detail/CVE-2022-37042
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925.
- packetstormsecurity.comhttp://packetstormsecurity.com/files/168146/Zimbra-Zip-Path-Traversal.html
- wiki.zimbra.comhttps://wiki.zimbra.com/wiki/Security_Center
- wiki.zimbra.comhttps://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
- packetstormsecurity.comhttp://packetstormsecurity.com/files/168146/Zimbra-Zip-Path-Traversal.html
- wiki.zimbra.comhttps://wiki.zimbra.com/wiki/Security_Center
- wiki.zimbra.comhttps://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
- www.cisa.govhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-37042