CVE-2022-3569
Due to an issue with incorrect sudo permissions, Zimbra Collaboration Suite (ZCS) suffers from a local privilege escalation issue in versions 9.0.0 and prior, where the 'zimbra' user can effectively coerce postfix into running arbitrary commands as…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.72%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Due to an issue with incorrect sudo permissions, Zimbra Collaboration Suite (ZCS) suffers from a local privilege escalation issue in versions 9.0.0 and prior, where the 'zimbra' user can effectively coerce postfix into running arbitrary commands as 'root'.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.72% probability · 52th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-271
- Affected
- synacor/zimbra collaboration suite
- Source
- cve@rapid7.com
References
- http://packetstormsecurity.com/files/169430/Zimbra-Privilege-Escalation.htmlExploit, Third Party Advisory, VDB Entry
- https://github.com/rapid7/metasploit-framework/pull/17141Exploit, Issue Tracking, Patch, Third Party Advisory
- https://twitter.com/ldsopreload/status/1580539318879547392Third Party Advisory
- http://packetstormsecurity.com/files/169430/Zimbra-Privilege-Escalation.htmlExploit, Third Party Advisory, VDB Entry
- https://github.com/rapid7/metasploit-framework/pull/17141Exploit, Issue Tracking, Patch, Third Party Advisory
- https://twitter.com/ldsopreload/status/1580539318879547392Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.