CVE-2022-3569: High severity zimbra collaboration suite vulnerability
Published Oct 17, 2022
·Updated
Due to an issue with incorrect sudo permissions, Zimbra Collaboration Suite (ZCS) suffers from a local privilege escalation issue in versions 9.0.0 and prior, where the 'zimbra' user can effectively coerce postfix into running arbitrary commands as 'root'.
Affected Software
1 affected component
Synacor Zimbra Collaboration Suite<=9.0.0
Remediation
Patch Available
Event History
Oct 17, 2022
CVE Published
via MITRE·10:45 PM
Data Sourced
via MITRE·10:45 PM
DescriptionWeakness
Data Sourced
via NVD·11:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-3569?
CVE-2022-3569 is a vulnerability in Zimbra Collaboration Suite (ZCS) that allows local privilege escalation.
2
What is the severity of CVE-2022-3569?
The severity of CVE-2022-3569 is high, with a CVSS score of 7.8.
3
Which versions of Zimbra Collaboration Suite are affected by CVE-2022-3569?
Versions 9.0.0 and prior of Zimbra Collaboration Suite are affected by CVE-2022-3569.
4
How does CVE-2022-3569 work?
CVE-2022-3569 is caused by incorrect sudo permissions, allowing the 'zimbra' user to run arbitrary commands as 'root'.
5
How can I fix CVE-2022-3569?
To fix CVE-2022-3569, update Zimbra Collaboration Suite to a version that is not affected by the vulnerability.