ZeroHour

CVE-2022-3569

PoC ×2
CVSS 3.1
7.8 high
EPSS
<1%p52
Published
()
Modified
Description

Due to an issue with incorrect sudo permissions, Zimbra Collaboration Suite (ZCS) suffers from a local privilege escalation issue in versions 9.0.0 and prior, where the 'zimbra' user can effectively coerce postfix into running arbitrary commands as 'root'.

Vendors
synacor
Products
zimbra collaboration suite
Weakness
CWE-271
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.