Executive brief
Synacor Zimbra Collaboration Suite (ZCS) allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These commands are processed without proper escaping, enabling the attacker to overwrite arbitrary cached entries.
Affected products
- Synacor Zimbra Collaboration Suite (ZCS) 8.8.15, 9.0.0
Timeline
- 2022-05-03: disclosed: Initial analysis by NIST
- 2022-08-04: kev added: Added to CISA Known Exploited Vulnerabilities Catalog