CVE-2022-27925

HIGH KEV RANSOMWARE

Zip Path Traversal in Zimbra (mboximport) (CVE-2022-27925)

Title source: metasploit

Description

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.

Exploits (13)

nomisec WORKING POC 66 stars
by vnhacker1337 · remote
https://github.com/vnhacker1337/CVE-2022-27925-PoC
nomisec WORKING POC 43 stars
by Josexv1 · remote
https://github.com/Josexv1/CVE-2022-27925
nomisec WORKING POC 18 stars
by SystemVll · remote
https://github.com/SystemVll/CVE-2022-27925
nomisec WRITEUP 8 stars
by jam620 · poc
https://github.com/jam620/Zimbra
nomisec WORKING POC 4 stars
by Chocapikk · remote
https://github.com/Chocapikk/CVE-2022-27925-Revshell
nomisec STUB 3 stars
by akincibor · remote
https://github.com/akincibor/CVE-2022-27925
nomisec WORKING POC 1 stars
by touchmycrazyredhat · remote
https://github.com/touchmycrazyredhat/CVE-2022-27925-Revshell
nomisec WORKING POC
by sanan2004 · remote
https://github.com/sanan2004/CVE-2022-27925
nomisec WORKING POC
by huahuatzt · poc
https://github.com/huahuatzt/CVE-2022-27925
nomisec WORKING POC
by navokus · poc
https://github.com/navokus/CVE-2022-27925
nomisec WORKING POC
by onlyHerold22 · remote
https://github.com/onlyHerold22/CVE-2022-27925-PoC
nomisec WORKING POC
by miko550 · poc
https://github.com/miko550/CVE-2022-27925

Scores

CVSS v3 7.2
EPSS 0.9431
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Exploitation Intel

CISA KEV 2022-08-11
VulnCheck KEV 2022-08-11
InTheWild.io 2022-08-11
ENISA EUVD EUVD-2022-32413
Ransomware Use Confirmed

Classification

CWE
CWE-22
Status published

Affected Products (50)

synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
... and 35 more

Timeline

Published Apr 21, 2022
KEV Added Aug 11, 2022
Tracked Since Feb 18, 2026