CVE-2022-37042
KEV RANSOMWARECRITICAL 9.8EPSS 91.9%
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 91.89% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2022-08-11, used in ransomware campaigns
- Nuclei
- critical · CWE-22
- Published
- 2022-08-11
- Updated
- 2026-08-04
Proof-of-concept exploits (5)
- http://packetstormsecurity.com/files/168146/Zimbra-Zip-Path-Traversal.html
- 0xf4n9x/CVE-2022-3704228★ · 2022-12-09
- Josexv1/CVE-2022-2792543★ · 2022-08-27
- aels/CVE-2022-3704218★ · 2022-08-29
- sanan2004/CVE-2022-279250★ · 2024-08-19