THREAT OPS › CVEs › CVE-2022-27925
CVE-2022-27925 — Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability
Synacor Zimbra Collaboration Suite (ZCS) contains flaw in the mboximport functionality, allowing an authenticated attacker to upload arbitrary files to perform remote code execution. This vulnerability was chained with CVE-2022-37042 which allows for unauthenticated remote code execution.
Vulnerability details
- Affected productsZimbra Collaboration Suite (ZCS)
- KEV remediation due2022-09-01
Related reporting
- August 2026 CVE Landscaperecordedfuture
- UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operationstalos
- [NVD] CVE-2022-37042 (CRITICAL 9.8) — Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal anvd
- [NVD] CVE-2022-27925 (HIGH 7.2) — Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.nvd
- [Security Blog] StrikeShark Campaign Exploits Known Vulnerabilities to Deploy Cobalt Strike via SharkLoaderhkcert
- June 2026 CVE Landscaperecordedfuture