CVE-2022-27924criticalunder attackransomwareCWE-74

CVE-2022-27924

Published · Updated

95Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.8epss 94%
from disclosure to weapon
Published on NVDApr 20
CISA KEV+106d
exploitation probability
94%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
Action required by CISAfederal deadline: 2022-08-25

Apply updates per vendor instructions.

In short

Zimbra Collaboration has a flaw that allows attackers without logging in to inject harmful commands into its cache memory system, potentially overwriting important stored data and disrupting service.

Technical detail

CVE-2022-27924 is an unauthenticated memcache injection vulnerability (CWE-74) in Zimbra Collaboration 8.8.15 and 9.0. The vulnerability stems from improper input validation allowing arbitrary memcache commands to be injected and executed unescaped, resulting in arbitrary cache entry overwrite and potential denial of service or information disclosure.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These memcache commands becomes unescaped, causing an overwrite of arbitrary cached entries.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a