RaqibCTI
CVE

CVE-2022-27925

P1⬤ KNOWN RANSOMWARE USE
Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability
Synacor · Zimbra Collaboration Suite (ZCS)
Date added (CISA)
2022-08-11
Remediation due
2022-09-01
Known ransomware use
Yes
Remediation priority
P1known ransomware use · past CISA due date
Associated with
Related to
  • Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroff · SPECTREcampaignCorrelated cluster2026-09-16
  • BadIIScampaignCorrelated cluster2026-08-26
  • SPECTREcampaignCorrelated cluster2026-08-20

Description

Synacor Zimbra Collaboration Suite (ZCS) contains flaw in the mboximport functionality, allowing an authenticated attacker to upload arbitrary files to perform remote code execution. This vulnerability was chained with CVE-2022-37042 which allows for unauthenticated remote code execution.

Source: NVD ↗ · CISA KEV Catalog ↗