KEVIntel
7.2
CVSS
High

CVE-2022-27925

PUBLISHED

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated...

Exploited in the wild Used in malware Remote Low complexity No user interaction
Vendor
Zimbra
Product
Collaboration
Published
Apr 20, 2022
EPSS

Description

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.

cisa malware ransomware metasploit

CVSS scores

CVSS v3.1 7.2 High

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0 6.5

AV:N/AC:L/Au:S/C:P/I:P/A:P

Exploitation status

Exploited in the wild

Recorded 2022-08-11 00:00:00 UTC · Source

Used in malware

Recorded 2022-08-11 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
No
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Aug 11, 2022

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

Inplex-sys/CVE-2022-27925

github · Created 2022-10-01 10:33:55 UTC · 16 stars

A loader for zimbra 2022 rce (cve-2022-27925)

touchmycrazyredhat/CVE-2022-27925-Revshell

github · Created 2022-09-17 22:24:32 UTC · 1 stars

akincibor/CVE-2022-27925

github · Created 2022-09-12 08:30:30 UTC · 2 stars

CVE-2022-27925 nuclei template

Chocapikk/CVE-2022-27925-Revshell

github · Created 2022-08-26 20:19:48 UTC · 4 stars

Python Script to exploit Zimbra Auth Bypass + RCE (CVE-2022-27925)

Josexv1/CVE-2022-27925

github · Created 2022-08-20 15:58:29 UTC · 43 stars

Zimbra CVE-2022-27925 PoC

mohamedbenchikh/CVE-2022-27925

github · Created 2022-08-14 22:22:55 UTC · 56 stars

Zimbra Unauthenticated Remote Code Execution Exploit (CVE-2022-27925)

vnhacker1337/CVE-2022-27925-PoC

github · Created 2022-08-12 18:35:52 UTC · 67 stars

Zimbra RCE simple poc

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Exploit Used in Malware

  • Added to KEVIntel

  • Detected by Metasploit