ZeroHour

CVE-2022-37393

PoC ×3
CVSS 3.1
7.8 high
EPSS
2%p75
Published
()
Modified
Description

Zimbra's sudo configuration permits the zimbra user to execute the zmslapd binary as root with arbitrary parameters. As part of its intended functionality, zmslapd can load a user-defined configuration file, which includes plugins in the form of .so files, which also execute as root.

Vendors
zimbra
Products
collaboration
Weakness
CWE-284
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.