August 11, 2022 · Applied Cybernetics Group
CVE-2022-37042 — Synacor Zimbra Collaboration Suite (ZCS)
known ransomware use
Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass Vulnerability
- Added to KEV
2022-08-11- Federal due date
2022-09-01- Vendor
- Synacor
- Product
- Zimbra Collaboration Suite (ZCS)
- EPSS
- 99.8th percentile (score 0.919, as of
2026-09-16) - NVD CVSS v3.1
- 9.8 (CRITICAL)
- Ransomware use
- Known
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2022-37042
CISA short description
Synacor Zimbra Collaboration Suite (ZCS) contains an authentication bypass vulnerability in MailboxImportServlet. This vulnerability was chained with CVE-2022-27925 which allows for unauthenticated remote code execution.
Required action
Apply updates per vendor instructions.
NVD description
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925.