PoC Index

CVE-2022-37042

KEV RANSOMWARECRITICAL 9.8EPSS 91.9%

Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
91.89% chance of exploitation in the next 30 days, 100th percentile
CISA KEV
added 2022-08-11, used in ransomware campaigns
Nuclei
critical · CWE-22
Published
2022-08-11
Updated
2026-08-04

Proof-of-concept exploits (5)

Nuclei templates (1)

Metasploit modules (1)

Exploit collections (1)

References

Related