Junglewise Threat Intelligence

CVE-2022-41352: Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability

CVE-2022-41352 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-10-20

Technologies: Synacor Zimbra Collaboration Suite (ZCS). Vendors: Synacor.

Executive brief

Synacor Zimbra Collaboration Suite (ZCS) is vulnerable to arbitrary file upload via a cpio loophole in the amavis component. An attacker can bypass security controls to extract files to the webapp directory, potentially gaining unauthorized access to user accounts. This issue occurs when the pax utility is missing, causing the system to fall back to cpio.

Affected products

  • Synacor Zimbra Collaboration Suite (ZCS) 8.8.15, 9.0.0

Timeline

  • 2022-10-20: disclosed
  • 2022-10-20: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-10-20: exploited: Reported as exploited in the wild

Related threats