CISA Known Exploited Vulnerability

CVE-2022-41352

Synacor · Zimbra Collaboration Suite (ZCS)

Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability

Date added
BOD 22-01 due date
CWE CWE-22
Ransomware Unknown

CISA description

Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to upload arbitrary files using cpio package to gain incorrect access to any other user accounts.

Required action

Apply updates per vendor instructions.