CVE-2022-27924: Zimbra Collaboration (ZCS) Command Injection Vulnerability
Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to inject memcache commands into a targeted instance which causes an overwrite of arbitrary cached entries.
Other sources
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These memcache commands becomes unescaped, causing an overwrite of arbitrary cached entries.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-27924?
The severity of CVE-2022-27924 is high with a CVSS score of 7.5.
How does CVE-2022-27924 affect Zimbra Collaboration (ZCS)?
CVE-2022-27924 affects Zimbra Collaboration (ZCS) versions 8.8.15 and 9.0.
How can an attacker exploit CVE-2022-27924?
An unauthenticated attacker can exploit CVE-2022-27924 by injecting arbitrary memcache commands into a targeted Zimbra Collaboration instance.
What is the impact of CVE-2022-27924?
CVE-2022-27924 allows an attacker to overwrite arbitrary cached entries, potentially leading to unauthorized access or denial of service.
How can I fix CVE-2022-27924?
To fix CVE-2022-27924, it is recommended to upgrade Zimbra Collaboration to a patched version.