Back

CRITICAL KEV Used in ransomware campaigns

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0

Published Sep 26, 2022 ·Due Nov 10, 2022

Description

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red Hat installation after RHEL 6 (or CentOS 6). Once pax is installed, amavis automatically prefers it over cpio.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 26, 2022
Updated Sep 10, 2026
Reserved Sep 26, 2022
CISA Vulnrichment
Updated Feb 3, 2025
NVD
Status Analyzed
Modified Sep 10, 2026
Red Hat
Severity n/a
Public date n/a