kevmap

Coverage › CVE-2022-27925

CVE-2022-27925 Unmapped

Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability

Vendor / product
Synacor — Zimbra Collaboration Suite (ZCS)
Description (CISA)
Synacor Zimbra Collaboration Suite (ZCS) contains flaw in the mboximport functionality, allowing an authenticated attacker to upload arbitrary files to perform remote code execution. This vulnerability was chained with CVE-2022-37042 which allows for unauthenticated remote code execution.
Added to KEV
2022-08-11
Due date
2022-09-01
Required action
Apply updates per vendor instructions.
Known ransomware use
Known
CWE
CWE-22
CISA notes
https://blog.zimbra.com/2022/08/authentication-bypass-in-mailboximportservlet-vulnerability/
https://nvd.nist.gov/vuln/detail/CVE-2022-27925
Elsewhere
cve.org · NVD · CISA KEV · JSON

ATT&CK techniques

No public source states how this vulnerability is exploited in ATT&CK terms.

The only authoritative CVE → ATT&CK mapping in the open — CTID's Mappings Explorer, pinned to a KEV snapshot of 2025-07-28 and ATT&CK 16.1 — does not include CVE-2022-27925. CISA's catalogue carries no technique field. kevmap does not infer techniques from the CWE (CWE-22) — here is why — and does not guess.

This page will change state automatically if a mapping is published. What is shown above is everything CISA publishes about the entry.

Sigma rules tagged with this CVE

1 rule in SigmaHQ carries the tag cve.2022-27925. These are shown as detection content for the CVE itself. Their ATT&CK tags are deliberately not rendered here: a rule author's tag is not an authoritative statement of how the vulnerability is exploited, and this page does not show techniques for unmapped entries.

Author: @gott_cyber · 2022-08-17 (modified 2023-01-02) · logsource: category=webserver · dd218fb6-4d02-42dc-85f0-a0a376072efd
Detects an attempt to leverage the vulnerable servlet "mboximport" for an unauthenticated remote command injection
CVE tags: CVE-2022-27925