Junglewise Threat Intelligence

CVE-2022-27924: Synacor Zimbra Collaboration Suite (ZCS) Command Injection Vulnerability

CVE-2022-27924 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2022-08-04

Technologies: Synacor Zimbra Collaboration Suite (ZCS). Vendors: Synacor.

Executive brief

Synacor Zimbra Collaboration Suite (ZCS) allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These commands are processed without proper escaping, enabling the attacker to overwrite arbitrary cached entries.

Affected products

  • Synacor Zimbra Collaboration Suite (ZCS) 8.8.15, 9.0.0

Timeline

  • 2022-05-03: disclosed: Initial analysis by NIST
  • 2022-08-04: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats