CVE-2022-37042
CRITICAL KEV RANSOMWARE NUCLEISynacor Zimbra Collaboration Suite - Path Traversal
Title source: ruleDescription
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925.
Exploits (5)
nomisec
WORKING POC
7 stars
by GreyNoise-Intelligence · poc
https://github.com/GreyNoise-Intelligence/Zimbra_CVE-2022-37042-_CVE-2022-27925
github
WRITEUP
2 stars
by Pr0t0c01 · pythonpoc
https://github.com/Pr0t0c01/CVEs/tree/main/Zimbra_CVE-2022-37042
metasploit
WORKING POC
EXCELLENT
by Volexity Threat Research, Yang_99, , # PoC · rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/zimbra_mboximport_cve_2022_27925.rb
Nuclei Templates (1)
Zimbra Collaboration Suite 8.8.15/9.0 - Remote Code Execution
CRITICALby _0xf4n9x_,For3stCo1d
Shodan:
http.favicon.hash:"1624375939" || http.favicon.hash:"475145467"
FOFA:
app="zimbra-邮件系统" || icon_hash="475145467" || icon_hash="1624375939"
References (4)
Scores
CVSS v3
9.8
EPSS
0.9433
EPSS Percentile
100.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation Intel
CISA KEV
2022-08-11
VulnCheck KEV
2022-08-10
InTheWild.io
2022-08-11
ENISA EUVD
EUVD-2022-39696
Ransomware Use
Confirmed
Classification
CWE
CWE-22
Status
published
Affected Products (50)
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
synacor/zimbra_collaboration_suite
... and 35 more
Timeline
Published
Aug 12, 2022
KEV Added
Aug 11, 2022
Tracked Since
Feb 18, 2026