Lucene search

K
cvelistRapid7CVELIST:CVE-2022-3569
HistoryOct 13, 2022 - 12:00 a.m.

CVE-2022-3569

2022-10-1300:00:00
CWE-271
rapid7
www.cve.org
1
zimbra collaboration suite
local privilege escalation
sudo permissions

0.002 Low

EPSS

Percentile

54.2%

Due to an issue with incorrect sudo permissions, Zimbra Collaboration Suite (ZCS) suffers from a local privilege escalation issue in versions 9.0.0 and prior, where the ‘zimbra’ user can effectively coerce postfix into running arbitrary commands as ‘root’.

CNA Affected

[
  {
    "vendor": "Synacor",
    "product": "Zimbra Collaboration Suite (ZCS)",
    "versions": [
      {
        "version": "9.0.0",
        "status": "affected",
        "lessThanOrEqual": "9.0.0",
        "versionType": "custom"
      }
    ]
  }
]

0.002 Low

EPSS

Percentile

54.2%

Related for CVELIST:CVE-2022-3569