---
id: CVE-2022-37042
title: >-
  Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality
  that receives a ZIP archive and extracts files from it
summary: >-
  Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality
  that receives a ZIP archive and extracts files from it. By bypassing
  authentication (i.e., not having an authtoken), an attacker can upload
  arbitrary files to t…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-22
  - CWE-22
vendor: synacor
product: zimbra_collaboration_suite
affected:
  - zimbra_collaboration_suite = 8.8.15
  - zimbra_collaboration_suite = 9.0.0
published: '2022-08-12'
updated: '2026-08-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-37042'
references:
  - url: 'http://packetstormsecurity.com/files/168146/Zimbra-Zip-Path-Traversal.html'
    label: cve@mitre.org
  - url: 'https://wiki.zimbra.com/wiki/Security_Center'
    label: cve@mitre.org
  - url: 'https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories'
    label: cve@mitre.org
  - url: 'http://packetstormsecurity.com/files/168146/Zimbra-Zip-Path-Traversal.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://wiki.zimbra.com/wiki/Security_Center'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-37042
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.91893
epssPercentile: 0.99816
kev: true
kevDateAdded: '2022-08-11'
kevDueDate: '2022-09-01'
kevRansomware: true
exploited: true
zeroDay: true
ingestedAt: '2026-08-04T05:36:12.365Z'
exploits:
  github: 3
  githubRepos:
    - >-
      https://github.com/GreyNoise-Intelligence/Zimbra_CVE-2022-37042-_CVE-2022-27925
    - 'https://github.com/aels/CVE-2022-37042'
    - 'https://github.com/0xf4n9x/CVE-2022-37042'
  metasploit:
    - exploit/linux/http/zimbra_mboximport_cve_2022_27925
  nuclei:
    - CVE-2022-37042
  checkedAt: '2026-09-25T08:20:41.058Z'
exploitAvailable: true
---

## Overview

Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925.

## Affected

- `zimbra_collaboration_suite = 8.8.15`
- `zimbra_collaboration_suite = 9.0.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
