Lucene search

K
cve[email protected]CVE-2022-3569
HistoryOct 17, 2022 - 11:15 p.m.

CVE-2022-3569

2022-10-1723:15:09
CWE-271
web.nvd.nist.gov
36
2
zimbra collaboration suite
zcs
cve-2022-3569
local privilege escalation
sudo
postfix
nvd

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.9 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

54.2%

Due to an issue with incorrect sudo permissions, Zimbra Collaboration Suite (ZCS) suffers from a local privilege escalation issue in versions 9.0.0 and prior, where the ‘zimbra’ user can effectively coerce postfix into running arbitrary commands as ‘root’.

Affected configurations

NVD
Node
synacorzimbra_collaboration_suiteRange9.0.0

CNA Affected

[
  {
    "vendor": "Synacor",
    "product": "Zimbra Collaboration Suite (ZCS)",
    "versions": [
      {
        "version": "9.0.0",
        "status": "affected",
        "lessThanOrEqual": "9.0.0",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.9 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

54.2%