CVE-2022-37393: Zimbra zmslapd arbitrary module load
Zimbra's sudo configuration permits the zimbra user to execute the zmslapd binary as root with arbitrary parameters. As part of its intended functionality, zmslapd can load a user-defined configuration file, which includes plugins in the form of .so files, which also execute as root.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-37393?
CVE-2022-37393 has been rated as high severity due to the potential for privilege escalation allowing unauthorized root access.
How do I fix CVE-2022-37393?
To mitigate CVE-2022-37393, update Zimbra Collaboration to the latest version that includes patches for this vulnerability.
What systems are affected by CVE-2022-37393?
CVE-2022-37393 affects specific versions of Zimbra Collaboration, including 8.7.6 to 8.7.11, 8.8.0 to 8.8.15, and 9.0.0.
What are the risks associated with CVE-2022-37393?
The primary risk with CVE-2022-37393 is that it allows an attacker to execute arbitrary commands with root privileges, compromising the entire system.
Is there active exploitation of CVE-2022-37393 reported?
Yes, there have been reports of active exploitation of CVE-2022-37393 in the wild, increasing the urgency for patches.