Lucene search

K
cvelistRapid7CVELIST:CVE-2022-37393
HistoryOct 27, 2021 - 12:00 a.m.

CVE-2022-37393 Zimbra zmslapd arbitrary module load

2021-10-2700:00:00
CWE-284
rapid7
www.cve.org
1

9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

45.3%

Zimbra’s sudo configuration permits the zimbra user to execute the zmslapd binary as root with arbitrary parameters. As part of its intended functionality, zmslapd can load a user-defined configuration file, which includes plugins in the form of .so files, which also execute as root.

CNA Affected

[
  {
    "product": "Zimbra Server",
    "vendor": "Synacor",
    "versions": [
      {
        "lessThanOrEqual": "9.0.0.p27",
        "status": "affected",
        "version": "9.0.0.p27",
        "versionType": "custom"
      },
      {
        "lessThanOrEqual": "8.8.15.p34",
        "status": "affected",
        "version": "8.8.15.p34",
        "versionType": "custom"
      }
    ]
  }
]

9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

45.3%