October 20, 2022 · Applied Cybernetics Group
CVE-2022-41352 — Synacor Zimbra Collaboration Suite (ZCS)
Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability
- Added to KEV
2022-10-20- Federal due date
2022-11-10- Vendor
- Synacor
- Product
- Zimbra Collaboration Suite (ZCS)
- EPSS
- 99.9th percentile (score 0.940, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2022-41352
CISA short description
Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to upload arbitrary files using cpio package to gain incorrect access to any other user accounts.
Required action
Apply updates per vendor instructions.