ZeroHour

CVE-2022-27924

KEV ransomwaremass

Unauthenticated Memcache Command Injection in Synacor Zimbra Collaboration Suite

CISA: Synacor Zimbra Collaboration Suite (ZCS) Command Injection Vulnerability

CVSS 3.1
7.5 high
EPSS
85%p100
Published
()
KEV added
AI analysis

Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 pass unauthenticated network input to memcache without escaping, allowing a remote attacker to inject arbitrary memcache commands (CWE-74). By sending crafted requests to Zimbra's exposed web/mail services, an attacker can poison the cache and overwrite arbitrary cached entries — a high-severity integrity impact that, in reported campaigns, has been used to tamper with cached data and steal users' login credentials. Any organization running unpatched ZCS 8.8.15 or 9.0 is affected, including the enterprise, ISP, and government mail deployments that make up Zimbra's installed base. Exploitation is ongoing and widespread: the flaw was added to CISA's Known Exploited Vulnerabilities Catalog on 2022-08-04 after mass exploitation, with known ransomware use, and EPSS assigns an 85.4% probability of exploitation within 30 days (100th percentile).

What to do: Apply the latest Zimbra patches for the 8.8.15 and 9.0 branches per the vendor's instructions, as required by CISA's KEV entry. As an interim mitigation, restrict memcache access (default TCP port 11211) so it cannot be reached through untrusted interfaces or the exposed mail/web services. Given known ransomware use, prioritize internet-facing Zimbra servers and review mail/web logs for signs of memcache command injection or cache tampering.

Affected
Synacor Zimbra Collaboration Suite (ZCS)8.8.15 and 9.0
Estimated exposure
mass≈50,000–100,000 internet-exposed Zimbra servers; total user base plausibly in the millions — Zimbra is a widely deployed enterprise, ISP, and government mail platform, and public internet-wide scans (Shodan/Censys) around the time of the 2022 exploitation wave showed tens of thousands of reachable Zimbra instances, implying an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These memcache commands becomes unescaped, causing an overwrite of arbitrary cached entries.

CISA Known Exploited Vulnerability
Affected
Synacor Zimbra Collaboration Suite (ZCS)
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
synacor
Products
zimbra collaboration suite
Weakness
CWE-74
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news