PT-2022-22944 · Zimbra · Zimbra Collaboration Suite
Ldsopreload
·
Published
2022-10-17
·
Updated
2025-05-13
·
CVE-2022-3569
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zimbra Collaboration Suite versions prior to 9.0.0
Description
The issue is related to incorrect sudo permissions, allowing a local privilege escalation where the
zimbra user can coerce postfix into running arbitrary commands as root.Recommendations
For versions prior to 9.0.0, update to version 9.0.0 or later to resolve the issue.
As a temporary workaround, consider restricting the
zimbra user's sudo permissions to prevent exploitation.
Restrict access to postfix to minimize the risk of arbitrary command execution as root.Exploit
Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zimbra Collaboration Suite