PT-2022-22944 · Zimbra · Zimbra Collaboration Suite

Ldsopreload

·

Published

2022-10-17

·

Updated

2025-05-13

·

CVE-2022-3569

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zimbra Collaboration Suite versions prior to 9.0.0
Description The issue is related to incorrect sudo permissions, allowing a local privilege escalation where the zimbra user can coerce postfix into running arbitrary commands as root.
Recommendations For versions prior to 9.0.0, update to version 9.0.0 or later to resolve the issue. As a temporary workaround, consider restricting the zimbra user's sudo permissions to prevent exploitation. Restrict access to postfix to minimize the risk of arbitrary command execution as root.

Exploit

Fix

LPE

Weakness Enumeration

Related Identifiers

CVE-2022-3569

Affected Products

Zimbra Collaboration Suite