7.8
CVE-2022-37393
- EPSS 1.67%
- Veröffentlicht 16.08.2022 20:15:07
- Zuletzt bearbeitet 21.11.2024 07:14:54
- Erkennungen
Zimbra zmslapd arbitrary module load
Zimbra's sudo configuration permits the zimbra user to execute the zmslapd binary as root with arbitrary parameters. As part of its intended functionality, zmslapd can load a user-defined configuration file, which includes plugins in the form of .so files, which also execute as root.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zimbra ≫ Collaboration Version 8.7.6
Zimbra ≫ Collaboration Version 8.7.7
Zimbra ≫ Collaboration Version 8.7.9
Zimbra ≫ Collaboration Version 8.7.10
Zimbra ≫ Collaboration Version 8.7.11 Update -
Zimbra ≫ Collaboration Version 8.7.11 Update p1
Zimbra ≫ Collaboration Version 8.7.11 Update p10
Zimbra ≫ Collaboration Version 8.7.11 Update p11
Zimbra ≫ Collaboration Version 8.7.11 Update p12
Zimbra ≫ Collaboration Version 8.7.11 Update p13
Zimbra ≫ Collaboration Version 8.7.11 Update p14
Zimbra ≫ Collaboration Version 8.7.11 Update p15
Zimbra ≫ Collaboration Version 8.7.11 Update p2
Zimbra ≫ Collaboration Version 8.7.11 Update p3
Zimbra ≫ Collaboration Version 8.7.11 Update p4
Zimbra ≫ Collaboration Version 8.7.11 Update p5
Zimbra ≫ Collaboration Version 8.7.11 Update p6
Zimbra ≫ Collaboration Version 8.7.11 Update p7
Zimbra ≫ Collaboration Version 8.7.11 Update p8
Zimbra ≫ Collaboration Version 8.7.11 Update p9
Zimbra ≫ Collaboration Version 8.8.0 Update beta1
Zimbra ≫ Collaboration Version 8.8.2
Zimbra ≫ Collaboration Version 8.8.3
Zimbra ≫ Collaboration Version 8.8.4
Zimbra ≫ Collaboration Version 8.8.6
Zimbra ≫ Collaboration Version 8.8.7
Zimbra ≫ Collaboration Version 8.8.8 Update -
Zimbra ≫ Collaboration Version 8.8.8 Update p1
Zimbra ≫ Collaboration Version 8.8.8 Update p3
Zimbra ≫ Collaboration Version 8.8.8 Update p4
Zimbra ≫ Collaboration Version 8.8.8 Update p7
Zimbra ≫ Collaboration Version 8.8.9 Update -
Zimbra ≫ Collaboration Version 8.8.9 Update p1
Zimbra ≫ Collaboration Version 8.8.9 Update p10
Zimbra ≫ Collaboration Version 8.8.9 Update p3
Zimbra ≫ Collaboration Version 8.8.10 Update -
Zimbra ≫ Collaboration Version 8.8.10 Update p8
Zimbra ≫ Collaboration Version 8.8.11 Update -
Zimbra ≫ Collaboration Version 8.8.11 Update p3
Zimbra ≫ Collaboration Version 8.8.11 Update p4
Zimbra ≫ Collaboration Version 8.8.11 Update p5
Zimbra ≫ Collaboration Version 8.8.12 Update -
Zimbra ≫ Collaboration Version 8.8.12 Update p3
Zimbra ≫ Collaboration Version 8.8.12 Update p4
Zimbra ≫ Collaboration Version 8.8.15 Update -
Zimbra ≫ Collaboration Version 8.8.15 Update p11
Zimbra ≫ Collaboration Version 8.8.15 Update p26
Zimbra ≫ Collaboration Version 8.8.15 Update p3
Zimbra ≫ Collaboration Version 8.8.15 Update p30
Zimbra ≫ Collaboration Version 8.8.15 Update p31
Zimbra ≫ Collaboration Version 8.8.15 Update p32
Zimbra ≫ Collaboration Version 8.8.15 Update p33
Zimbra ≫ Collaboration Version 8.8.15 Update p34
Zimbra ≫ Collaboration Version 8.8.15 Update p5
Zimbra ≫ Collaboration Version 9.0.0 Update p0
Zimbra ≫ Collaboration Version 9.0.0 Update p19
Zimbra ≫ Collaboration Version 9.0.0 Update p23
Zimbra ≫ Collaboration Version 9.0.0 Update p25
Zimbra ≫ Collaboration Version 9.0.0 Update p26
Zimbra ≫ Collaboration Version 9.0.0 Update p27
Zimbra ≫ Collaboration Version 9.0.0 Update p4
Zimbra ≫ Collaboration Version 9.0.0 Update p7
Zimbra ≫ Collaboration Version 9.0.0 Update p7.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.67% | 0.747 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
https://attackerkb.com/topics/92AeLOE1M1/cve-2022-37393/rapid7-analysis
https://darrenmartyn.ie/2021/10/27/zimbra-zmslapd-local-root-exploit/
https://github.com/rapid7/metasploit-framework/pull/16807