PT-2022-3567 · Zimbra · Zimbra Collaboration

Simon Scannell

·

Published

2022-04-20

·

Updated

2026-01-06

·

CVE-2022-27924

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Zimbra Collaboration (aka ZCS) versions 8.8.15 through 9.0.0
Description The issue allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance, causing an overwrite of arbitrary cached entries. This can be exploited to execute arbitrary commands and potentially steal user credentials. The vulnerability is being actively exploited.
Recommendations For Zimbra Collaboration (aka ZCS) versions 8.8.15 through 9.0.0, update to version 8.8.15 P31.1 or 9.0.0 P24.1 to resolve the issue. As a temporary workaround, consider restricting access to memcache commands to minimize the risk of exploitation.

Fix

Special Elements Injection

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2022-04351
CVE-2022-27924

Affected Products

Zimbra Collaboration