Vulnerability record · CVE-2022-37042 · published 12 August 2022
CVE-2022-37042: Zimbra Collaboration Suite mboximport auth bypass path traversal RCE
SSynacor · Zimbra Collaboration Suite
Zimbra Collaboration Suite 8.8.15 and 9.0 mboximport accepts a ZIP archive and extracts files without requiring an authtoken, allowing unauthenticated upload of arbitrary files. The incomplete fix for CVE-2022-27925 leaves a path traversal that can lead to remote code execution.
Description
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network RCE with active exploitation, KEV listing, ransomware use, and near-maximum EPSS.
What it is
Zimbra Collaboration Suite 8.8.15 and 9.0 mboximport accepts a ZIP archive and extracts files without requiring an authtoken, allowing unauthenticated upload of arbitrary files. The incomplete fix for CVE-2022-27925 leaves a path traversal that can lead to remote code execution.
Impact
An unauthenticated attacker can write arbitrary files to the server and achieve remote code execution, gaining full control of the Zimbra host.
Attack surface
Reachable over the network via the mboximport functionality; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
CISA KEV lists it as actively exploited with known ransomware campaign use, and EPSS is 0.91893 (99.8th percentile); a public exploit reference exists.
What to do
- Apply the vendor patch from the Zimbra Security Center immediately.
- Restrict network access to Zimbra administrative and mboximport endpoints to trusted sources.
- Verify the CVE-2022-27925 fix is fully applied, since this is an incomplete-fix bypass.
- Monitor for unexpected file writes or web shells in Zimbra directories.
Detection
- Inspect Zimbra logs for mboximport requests lacking a valid authtoken.
- Alert on ZIP uploads containing path traversal sequences such as ../.
- Monitor for new or modified executable files in Zimbra web and mail directories.
- Correlate outbound connections from the Zimbra host with file-write events.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-37042 to the Known Exploited Vulnerabilities catalog on 11 August 2022 as "Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 1 September 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/168146/Zimbra-Zip-Path-Traversal.html | ExploitThird Party AdvisoryVDB Entry |
| https://wiki.zimbra.com/wiki/Security_Center | PatchVendor Advisory |
| https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories | Vendor Advisory |
| http://packetstormsecurity.com/files/168146/Zimbra-Zip-Path-Traversal.html | ExploitThird Party AdvisoryVDB Entry |
| https://wiki.zimbra.com/wiki/Security_Center | PatchVendor Advisory |
| https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-37042 | US Government Resource |
Track CVE-2022-37042 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-37042), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.