CRITICAL KEV Used in ransomware campaigns ⚠
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0
Published Sep 26, 2022 ·Due Nov 10, 2022
9.8
CRITICALCVSS 3.1
EPSS 95.48%
Description
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red Hat installation after RHEL 6 (or CentOS 6). Once pax is installed, amavis automatically prefers it over cpio.
Affected products
No data.
Configuration 1
OR
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
Configuration 2
OR
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- http://packetstormsecurity.com/files/169458/Zimbra-Collaboration-Suite-TAR-Path-Traversal.html ExploitThird Party AdvisoryVDB Entry
- https://forums.zimbra.org/viewtopic.php?t=71153&p=306532 MitigationVendor Advisory
- https://wiki.zimbra.com/wiki/Security_Center PatchRelease NotesVendor Advisory
- https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-41352 government-resourceUS Government Resource
- https://www.secpod.com/blog/unpatched-rce-bug-in-zimbra-collaboration-suite-exploited-in-wild/ Third Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://packetstormsecurity.com/files/169458/Zimbra-Collaboration-Suite-TAR-Path-Traversal.html | ExploitThird Party AdvisoryVDB Entry | |
| https://forums.zimbra.org/viewtopic.php?t=71153&p=306532 | MitigationVendor Advisory | |
| https://wiki.zimbra.com/wiki/Security_Center | PatchRelease NotesVendor Advisory | |
| https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories | Vendor Advisory | |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-41352 | government-resourceUS Government Resource | |
| https://www.secpod.com/blog/unpatched-rce-bug-in-zimbra-collaboration-suite-exploited-in-wild/ | Third Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 26, 2022
Updated Sep 10, 2026
Reserved Sep 26, 2022
Link CVE-2022-41352
CISA Vulnrichment
Updated Feb 3, 2025