← Back

CVE-2022-37393

nvd nist
Published: Aug 16, 2022Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

Zimbra's sudo configuration permits the zimbra user to execute the zmslapd binary as root with arbitrary parameters. As part of its intended functionality, zmslapd can load a user-defined configuration file, which includes plugins in the form of .so files, which also execute as root.

Affected (63)

1 product
Collaboration
Configuration A
63 vulnerable
Vulnerable SoftwareAffected Versions
Zimbra
Version 8.7.10
Version 8.7.11
Version 8.7.11 p10
Version 8.7.11 p11
Version 8.7.11 p12
Version 8.7.11 p13
Version 8.7.11 p14
Version 8.7.11 p15
Version 8.7.11 p1
Version 8.7.11 p2
Version 8.7.11 p3
Version 8.7.11 p4
Version 8.7.11 p5
Version 8.7.11 p6
Version 8.7.11 p7
Version 8.7.11 p8
Version 8.7.11 p9
Version 8.7.6
Version 8.7.7
Version 8.7.9
Version 8.8.0 beta1
Version 8.8.10
Version 8.8.10 p8
Version 8.8.11
Version 8.8.11 p3
Version 8.8.11 p4
Version 8.8.11 p5
Version 8.8.12
Version 8.8.12 p3
Version 8.8.12 p4
Version 8.8.15
Version 8.8.15 p11
Version 8.8.15 p26
Version 8.8.15 p30
Version 8.8.15 p31
Version 8.8.15 p32
Version 8.8.15 p33
Version 8.8.15 p34
Version 8.8.15 p3
Version 8.8.15 p5
Version 8.8.2
Version 8.8.3
Version 8.8.4
Version 8.8.6
Version 8.8.7
Version 8.8.8
Version 8.8.8 p1
Version 8.8.8 p3
Version 8.8.8 p4
Version 8.8.8 p7
Version 8.8.9
Version 8.8.9 p10
Version 8.8.9 p1
Version 8.8.9 p3
Version 9.0.0 p0
Version 9.0.0 p19
Version 9.0.0 p23
Version 9.0.0 p25
Version 9.0.0 p26
Version 9.0.0 p27
Version 9.0.0 p4
Version 9.0.0 p7.1
Version 9.0.0 p7

References (6)

Source: cve@rapid7.com
ExploitThird Party Advisory
Source: cve@rapid7.com
ExploitThird Party Advisory
Source: cve@rapid7.com
ExploitPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchThird Party Advisory

Timeline

No history available yet.