{"id":"CVE-2022-41352","title":"An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0","summary":"An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to …","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-22"],"vendor":"synacor","product":"zimbra_collaboration_suite","affected":["zimbra_collaboration_suite = 9.0.0","zimbra_collaboration_suite = 8.8.15"],"published":"2022-09-26","updated":"2026-09-10","sourceUpdated":"2026-09-10T04:17:37.410","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2022-41352","references":[{"url":"http://packetstormsecurity.com/files/169458/Zimbra-Collaboration-Suite-TAR-Path-Traversal.html","label":"cve@mitre.org"},{"url":"https://forums.zimbra.org/viewtopic.php?t=71153&p=306532","label":"cve@mitre.org"},{"url":"https://wiki.zimbra.com/wiki/Security_Center","label":"cve@mitre.org"},{"url":"https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories","label":"cve@mitre.org"},{"url":"https://www.secpod.com/blog/unpatched-rce-bug-in-zimbra-collaboration-suite-exploited-in-wild/","label":"cve@mitre.org"},{"url":"http://packetstormsecurity.com/files/169458/Zimbra-Collaboration-Suite-TAR-Path-Traversal.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://forums.zimbra.org/viewtopic.php?t=71153&p=306532","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://wiki.zimbra.com/wiki/Security_Center","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.secpod.com/blog/unpatched-rce-bug-in-zimbra-collaboration-suite-exploited-in-wild/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-41352","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","in-the-wild","exploit-available","kev"],"exploited":true,"exploitAvailable":true,"ssvc":{"exploitation":"active","automatable":"yes","technicalImpact":"total","timestamp":"2022-10-07T00:00:00+00:00"},"ingestedAt":"2026-09-13T03:15:14.507Z","epss":0.95478,"epssPercentile":0.99869,"kev":true,"kevDateAdded":"2022-10-20","kevDueDate":"2022-11-10","kevRansomware":true,"exploits":{"github":3,"githubRepos":["https://github.com/segfault-it/cve-2022-41352","https://github.com/Cr4ckC4t/cve-2022-41352-zimbra-rce","https://github.com/dafrax/cve-2022-41352-zimbra-rce"],"metasploit":["exploit/linux/http/zimbra_cpio_cve_2022_41352"],"nuclei":["CVE-2022-41352"],"checkedAt":"2026-09-21T15:25:30.940Z"},"slug":"CVE-2022-41352","body":"## Overview\n\nAn issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red Hat installation after RHEL 6 (or CentOS 6). Once pax is installed, amavis automatically prefers it over cpio.\n\n## Affected\n\n- `zimbra_collaboration_suite = 9.0.0`\n- `zimbra_collaboration_suite = 8.8.15`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"hadal","depthScore":100,"depthScoreParts":{"impact":53.9,"likelihood":19.1,"exploitation":25,"ransomware":5},"changes":[]}