CVE-2022-27924
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply updates per vendor instructions.
Zimbra Collaboration has a flaw that allows attackers without logging in to inject harmful commands into its cache memory system, potentially overwriting important stored data and disrupting service.
CVE-2022-27924 is an unauthenticated memcache injection vulnerability (CWE-74) in Zimbra Collaboration 8.8.15 and 9.0. The vulnerability stems from improper input validation allowing arbitrary memcache commands to be injected and executed unescaped, resulting in arbitrary cache entry overwrite and potential denial of service or information disclosure.
The full analysis of this CVE is available in Portuguese →