CVE-2022-27925: Zimbra Collaboration (ZCS) Arbitrary File Upload Vulnerability
Synacor Zimbra Collaboration Suite (ZCS) contains flaw in the mboximport functionality, allowing an authenticated attacker to upload arbitrary files to perform remote code execution. This vulnerability was chained with CVE-2022-37042 which allows for unauthenticated remote code execution.
Other sources
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-27925?
CVE-2022-27925 is a vulnerability in Zimbra Collaboration (ZCS) that allows an authenticated attacker to upload arbitrary files and perform remote code execution.
How severe is CVE-2022-27925?
CVE-2022-27925 has a severity rating of 7.2 (high).
What software versions are affected by CVE-2022-27925?
Zimbra Collaboration versions 8.8.15 and 9.0.0 are affected by CVE-2022-27925.
How can an attacker exploit CVE-2022-27925?
An attacker can exploit CVE-2022-27925 by using the mboximport functionality to upload arbitrary files and execute remote code.
Are there any fixes or patches available for CVE-2022-27925?
Yes, Zimbra Collaboration release 9.0.0 Patch 24 contains a fix for CVE-2022-27925.