August 4, 2022 · Applied Cybernetics Group
CVE-2022-27924 — Synacor Zimbra Collaboration Suite (ZCS)
known ransomware use
Synacor Zimbra Collaboration Suite (ZCS) Command Injection Vulnerability
- Added to KEV
2022-08-04- Federal due date
2022-08-25- Vendor
- Synacor
- Product
- Zimbra Collaboration Suite (ZCS)
- EPSS
- 99.7th percentile (score 0.854, as of
2026-09-16) - NVD CVSS v3.1
- 7.5 (HIGH)
- Ransomware use
- Known
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2022-27924
CISA short description
Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to inject memcache commands into a targeted instance which causes an overwrite of arbitrary cached entries.
Required action
Apply updates per vendor instructions.
NVD description
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These memcache commands becomes unescaped, causing an overwrite of arbitrary cached entries.