Description
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.
In plain language
AI Act nowIf you run Zimbra Collaboration Suite, a logged-in administrator can upload a ZIP file to the mboximport feature and have it extract files anywhere on the server—this has been used in ransomware-related attacks, so you should fix it urgently.
In Zimbra Collaboration Suite, mboximport processes uploaded ZIP archives such that an authenticated administrator can trigger directory traversal/arbitrary file placement (CWE-22), and the flaw is listed in CISA KEV as used in ransomware campaigns.
What to do now
- Check whether your Zimbra Collaboration Suite version is 8.8.15 or 9.0, and whether the mboximport/upload process is available to administrator users.
- Review your current admin accounts and confirm whether any accounts could be used by an attacker.
- Upgrade Zimbra Collaboration Suite to the vendor-fixed release(s) listed in Zimbra’s Security Center and the Zimbra 9.0.0 Patch 24 materials.
- If you cannot upgrade immediately, disable or restrict access to the mboximport ZIP import capability and limit administrator access to only trusted accounts, then document the temporary controls until the upgrade is completed.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:HPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2022-27925 and every CVE in our database. Create a free account — no credit card required.
Create Free Account