Vulnerability record · CVE-2022-27925 · published 21 April 2022
CVE-2022-27925: Zimbra Collaboration mboximport ZIP path traversal allows arbitrary file upload
SSynacor · Zimbra Collaboration Suite
Zimbra Collaboration Suite 8.8.15 and 9.0 mboximport functionality accepts a ZIP archive and extracts files without properly validating paths, allowing directory traversal. An authenticated administrator can upload arbitrary files to the system, which can lead to code execution or full compromise of the mail server.
Description
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityThe vulnerability is in CISA KEV with known ransomware use, has a very high EPSS score, and allows an authenticated administrator to achieve arbitrary file write and likely remote code execution.
What it is
Zimbra Collaboration Suite 8.8.15 and 9.0 mboximport functionality accepts a ZIP archive and extracts files without properly validating paths, allowing directory traversal. An authenticated administrator can upload arbitrary files to the system, which can lead to code execution or full compromise of the mail server.
Impact
An attacker with administrative rights can write files to arbitrary locations on the server, enabling web shell placement, configuration tampering, or remote code execution. This can result in complete compromise of the Zimbra host and access to mail data.
Attack surface
The flaw is reachable over the network via the mboximport feature, requiring authentication with administrator privileges and no user interaction. The CVSS vector confirms network access, low complexity, and high privileges required.
Exploitation
CVE-2022-27925 is listed in CISA KEV with known ransomware campaign use, and EPSS indicates a very high probability of exploitation. Public exploit references are available, confirming active exploitation in the wild.
What to do
- Apply the vendor updates referenced in Zimbra Security Advisories and release notes (e.g., 9.0.0 P24) as soon as possible.
- Restrict administrative access to the Zimbra administration console and mboximport functionality to trusted networks or IP allowlists.
- Enforce strong authentication and monitor for unauthorized administrative account usage.
- If patching is not immediately possible, consider disabling or restricting the mboximport feature until updates are applied.
- Review and harden file upload and extraction paths to prevent traversal, following vendor guidance.
Detection
- Monitor Zimbra server logs for mboximport requests, especially those containing ZIP archives with path traversal sequences (e.g., ../).
- Alert on unexpected file creation or modification in web-accessible directories or system paths outside normal Zimbra data directories.
- Hunt for known web shell indicators or suspicious files in Zimbra web directories following mboximport activity.
- Correlate administrative login events with subsequent file upload or extraction activity for anomalous behavior.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-27925 to the Known Exploited Vulnerabilities catalog on 11 August 2022 as "Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 1 September 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/168146/Zimbra-Zip-Path-Traversal.html | ExploitThird Party AdvisoryVDB Entry |
| https://wiki.zimbra.com/wiki/Security_Center | Vendor Advisory |
| https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P24 | Release NotesVendor Advisory |
| https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories | Vendor Advisory |
| http://packetstormsecurity.com/files/168146/Zimbra-Zip-Path-Traversal.html | ExploitThird Party AdvisoryVDB Entry |
| https://wiki.zimbra.com/wiki/Security_Center | Vendor Advisory |
| https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P24 | Release NotesVendor Advisory |
| https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-27925 | US Government Resource |
Track CVE-2022-27925 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-27925), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.