PT-2023-2845 · Zimbra · Zimbra Collaboration Suite
Ali Dinifar
·
Published
2023-02-21
·
Updated
2023-06-27
·
CVE-2023-24032
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zimbra Collaboration Suite versions 8.8.15 through 9.0
Description
The issue in Zimbra Collaboration Suite is related to the use of certain JVM arguments in the mailbox manager, which can be exploited by an attacker with initial user access to a Zimbra server instance. This can lead to local privilege escalation (LPE) by executing commands as root. The exploitation of this issue may allow a remote attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations
For Zimbra Collaboration Suite versions 8.8.15 through 9.0, consider disabling the use of JVM arguments in the mailbox manager as a temporary workaround until a patch is available. Restrict access to the mailbox manager to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zimbra Collaboration Suite