KEVIntel
7.5
CVSS
High

CVE-2022-27924

PUBLISHED

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance....

Exploited in the wild Used in malware Remote Low complexity No user interaction
Vendor
Zimbra
Product
Zimbra Collaboration
Published
Apr 20, 2022
EPSS

Description

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These memcache commands becomes unescaped, causing an overwrite of arbitrary cached entries.

cisa malware nuclei_scanner nessus_scanner

CVSS scores

CVSS v3.1 7.5 High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CVSS v2.0 5.0

AV:N/AC:L/Au:N/C:N/I:P/A:N

Exploitation status

Exploited in the wild

Recorded 2022-08-04 00:00:00 UTC · Source

Used in malware

Recorded 2026-06-02 14:08:25 UTC · Source

SSVC decision points

Exploitation
active
Automatable
Yes
Technical impact
partial

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Aug 04, 2022

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Nessus

  • Detected by Nuclei

  • Exploit Used in Malware