Record summary

CVE-2022-41352 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit, 4 repository PoCs, and 1 Nuclei template. CISA lists CVE-2022-41352 in KEV; VulnCheck reports CVE-2022-41352 use in known ransomware campaigns.

Description

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red Hat installation after RHEL 6 (or CentOS 6). Once pax is installed, amavis automatically prefers it over cpio.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Oct 20, 2022 · CISA
VulnCheck KEV
Listed · Oct 20, 2022 · VulnCheck
Reported exploitation
Observed · VulnCheck
Ransomware use
Observed · VulnCheck

Available material

Catalogued exploits
1
Repository PoCs
4
Nuclei templates
1

CISA SSVC decision

ExploitationActive
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 3, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CISAVersion data not supplied

Proofs of concept

5

Catalogued exploits

MetasploitTAR Path Traversal in Zimbra (CVE-2022-41352)Metasploit exploitby Alexander Cherepanov +2 moreNot analyzed1 file

Ruby · linked to 2 vulnerabilities

Metasploit

PoC details

Repository PoCs

GitHubsegfault-it/cve-2022-41352Repository PoCby segfault-itStars: 8Not analyzed4 files

23.0 KiB

GitHub

PoC details
GitHubCr4ckC4t/cve-2022-41352-zimbra-rceRepository PoCby Cr4ckC4tStars: 109Not analyzed2 files

10.3 KiB

GitHub

PoC details
GitHubqailanet/cve-2022-41352-zimbra-rceRepository PoCby qailanetStars: 0Not analyzed1 file

879 B

GitHub

PoC details
GitHubrxerium/CVE-2022-41352Repository PoCby rxeriumStars: 2Not analyzed3 files

3.4 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALZimbra Collaboration - Unrestricted File UploadCVSS 9.8

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red Hat installation after RHEL 6 (or CentOS 6). Once pax is installed, amavis automatically prefers it over cpio.

Impact

Unauthenticated attackers can upload arbitrary files through amavis via a cpio loophole that extracts to the webapps directory, potentially achieving remote code execution and unauthorized access to other user accounts in Zimbra Collaboration Suite.

Remediation

Install pax package and ensure amavis is configured to use pax instead of cpio. Update to the latest patched version of Zimbra Collaboration Suite.

WeaknessesCWE-22
Authorsrxerium
Template tagscvecve2022zimbrakevfile-uploadpassivevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:zimbra:collaboration:8.8.15:-:*:*:*:*:*:*
Shodan: http.favicon.hash:"1624375939"
Shodan: http.html:"Zimbra Collaboration Suite Web Client"
FOFA: icon_hash="1624375939"

Source: ProjectDiscovery

References

7