Vulnerability record · CVE-2022-41352 · published 26 September 2022
CVE-2022-41352: Zimbra Collaboration amavis cpio path traversal arbitrary file upload
SSynacor · Zimbra Collaboration Suite
Zimbra Collaboration Suite 8.8.15 and 9.0 allow an attacker to upload arbitrary files through amavis by abusing cpio archive extraction into the web-accessible /opt/zimbra/jetty/webapps/zimbra/public directory. Because the extracted files land under a served path, the flaw enables code or content placement that can lead to access to other user accounts. It is a critical, remotely reachable flaw with no authentication or user interaction required.
Description
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red Hat installation after RHEL 6 (or CentOS 6). Once pax is installed, amavis automatically prefers it over cpio.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-exploitable file upload leading to code execution, listed in KEV with known ransomware use and near-maximum EPSS.
What it is
Zimbra Collaboration Suite 8.8.15 and 9.0 allow an attacker to upload arbitrary files through amavis by abusing cpio archive extraction into the web-accessible /opt/zimbra/jetty/webapps/zimbra/public directory. Because the extracted files land under a served path, the flaw enables code or content placement that can lead to access to other user accounts. It is a critical, remotely reachable flaw with no authentication or user interaction required.
Impact
An unauthenticated attacker can write arbitrary files into a web-served directory, which can lead to remote code execution and compromise of the mail server, including access to other users' accounts.
Attack surface
Reached over the network through the amavis mail-processing path that handles inbound mail attachments; the CVSS vector shows no privileges and no user interaction required.
Exploitation
CVE-2022-41352 is in CISA's Known Exploited Vulnerabilities catalog with known ransomware campaign use, and EPSS gives a 30-day probability of 0.95478 (99.867th percentile); public exploit code is referenced.
What to do
- Apply the vendor patch per Zimbra security advisories and Security Center guidance.
- Install pax so amavis prefers it over cpio, as Zimbra recommends, especially on Red Hat/CentOS systems where pax is absent after RHEL/CentOS 6.
- If patching is delayed, restrict or disable amavis handling of untrusted archive attachments until pax is in place.
- Verify the web-served public directory does not contain unexpected files and monitor it for new writes.
- Treat this as an emergency change given KEV listing and ransomware use.
Detection
- Monitor /opt/zimbra/jetty/webapps/zimbra/public for unexpected new or modified files.
- Alert on cpio extraction activity by amavis and on archive attachments processed without pax present.
- Hunt for web requests to newly written files under the public web path.
- Review mail logs for suspicious archive attachments routed through amavis around the time of file creation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-41352 to the Known Exploited Vulnerabilities catalog on 20 October 2022 as "Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 10 November 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-41352 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-41352), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.