Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Ldsopreload

#32770of 53,630
7.8Total CVSS
Vulnerabilities · 1
PT-2022-22944
7.8
2022-10-17
Zimbra · Zimbra Collaboration Suite · CVE-2022-3569
**Name of the Vulnerable Software and Affected Versions** Zimbra Collaboration Suite versions prior to 9.0.0 **Description** The issue is related to incorrect sudo permissions, allowing a local privilege escalation where the `zimbra` user can coerce postfix into running arbitrary commands as `root`. **Recommendations** For versions prior to 9.0.0, update to version 9.0.0 or later to resolve the issue. As a temporary workaround, consider restricting the `zimbra` user's sudo permissions to prevent exploitation. Restrict access to postfix to minimize the risk of arbitrary command execution as `root`.