CVE-2022-37042
KEV
🔴 Łataj teraz
Obejście uwierzytelnienia w Zimbra Collaboration Suite pozwala na zdalne wykonanie kodu.
CVSS
9.8
EPSS
88.8%
Exploit
weaponized
Vendor
synacor
Opis źródłowy (NVD)
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925.
exploit path-traversal rce
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.8 |
| CISA KEV (aktywnie wykorzystywane) | Tak |
| FIRST EPSS (prawdopodobieństwo exploita) | 88.8% |
| Opublikowano (NVD) | 2022-08-12 15:15:16 UTC |
| Ostatnia modyfikacja (NVD) | 2026-08-04 05:16:29 UTC |
Referencje
- http://packetstormsecurity.com/files/168146/Zimbra-Zip-Path-Traversal.html (cve@mitre.org) [Exploit, Third Party Advisory, VDB Entry]
- https://wiki.zimbra.com/wiki/Security_Center (cve@mitre.org) [Patch, Vendor Advisory]
- https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories (cve@mitre.org) [Vendor Advisory]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-37042 (134c704f-9b21-4f2e-91b3-4a467353bcc0) [US Government Resource]