CVE-2022-37042: Zimbra Collaboration (ZCS) Authentication Bypass Vulnerability
Synacor Zimbra Collaboration Suite (ZCS) contains an authentication bypass vulnerability in MailboxImportServlet. This vulnerability was chained with CVE-2022-27925 which allows for unauthenticated remote code execution.
Other sources
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-37042?
CVE-2022-37042 is a vulnerability in Zimbra Collaboration Suite (ZCS) that allows an attacker to bypass authentication and upload arbitrary files to the system, leading to directory traversal and remote code execution.
How does CVE-2022-37042 impact Zimbra Collaboration Suite?
CVE-2022-37042 allows attackers to bypass authentication and upload arbitrary files to the system, which can lead to directory traversal and remote code execution.
Which versions of Zimbra Collaboration Suite are affected by CVE-2022-37042?
Zimbra Collaboration Suite versions 8.8.15 and 9.0.0 are affected by CVE-2022-37042.
What is the severity rating of CVE-2022-37042?
CVE-2022-37042 has a severity rating of 9.8 (critical).
How can I mitigate the CVE-2022-37042 vulnerability?
To mitigate the CVE-2022-37042 vulnerability, it is recommended to update Zimbra Collaboration Suite to a patched version provided by the vendor.