CVE-2022-27925
HIGH KEV RANSOMWAREZip Path Traversal in Zimbra (mboximport) (CVE-2022-27925)
Title source: metasploitDescription
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.
Exploits (13)
nomisec
WORKING POC
66 stars
by vnhacker1337 · remote
https://github.com/vnhacker1337/CVE-2022-27925-PoC
nomisec
WORKING POC
4 stars
by Chocapikk · remote
https://github.com/Chocapikk/CVE-2022-27925-Revshell
nomisec
WORKING POC
1 stars
by touchmycrazyredhat · remote
https://github.com/touchmycrazyredhat/CVE-2022-27925-Revshell
References (5)
Scores
CVSS v3
7.2
EPSS
0.9431
EPSS Percentile
99.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitation Intel
CISA KEV
2022-08-11
VulnCheck KEV
2022-08-11
InTheWild.io
2022-08-11
ENISA EUVD
EUVD-2022-32413
Ransomware Use
Confirmed
Classification
CWE
CWE-22
Status
published
Affected Products (50)
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
... and 35 more
Timeline
Published
Apr 21, 2022
KEV Added
Aug 11, 2022
Tracked Since
Feb 18, 2026