CVE-2022-37393
Last modified
CVE-2022-37393 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Zimbra's sudo configuration permits the zimbra user to execute the zmslapd binary as root with arbitrary parameters. As part of its intended functionality, zmslapd can load a user-defined configuration file, which includes plugins in the form of .so files, which also execute as root.. EPSS estimates a 1.68% chance of exploitation in the next 30 days.
Description
Zimbra's sudo configuration permits the zimbra user to execute the zmslapd binary as root with arbitrary parameters. As part of its intended functionality, zmslapd can load a user-defined configuration file, which includes plugins in the form of .so files, which also execute as root.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Zimbra | Collaboration | 8.7.6 | — |
| Zimbra | Collaboration | 8.7.7 | — |
| Zimbra | Collaboration | 8.7.9 | — |
| Zimbra | Collaboration | 8.7.10 | — |
| Zimbra | Collaboration | 8.7.11 | — |
| Zimbra | Collaboration | 8.8.0 | Beta1 |
| Zimbra | Collaboration | 8.8.2 | — |
| Zimbra | Collaboration | 8.8.3 | — |
| Zimbra | Collaboration | 8.8.4 | — |
| Zimbra | Collaboration | 8.8.6 | — |
| Zimbra | Collaboration | 8.8.7 | — |
| Zimbra | Collaboration | 8.8.8 | — |
| Zimbra | Collaboration | 8.8.9 | — |
| Zimbra | Collaboration | 8.8.10 | — |
| Zimbra | Collaboration | 8.8.11 | — |
| Zimbra | Collaboration | 8.8.12 | — |
| Zimbra | Collaboration | 8.8.15 | — |
| Zimbra | Collaboration | 9.0.0 | P0 |
References
- https://attackerkb.com/topics/92AeLOE1M1/cve-2022-37393/rapid7-analysisExploit, Third Party Advisory
- https://darrenmartyn.ie/2021/10/27/zimbra-zmslapd-local-root-exploit/Exploit, Third Party Advisory
- https://github.com/rapid7/metasploit-framework/pull/16807Exploit, Patch, Third Party Advisory
- https://attackerkb.com/topics/92AeLOE1M1/cve-2022-37393/rapid7-analysisExploit, Third Party Advisory
- https://darrenmartyn.ie/2021/10/27/zimbra-zmslapd-local-root-exploit/Exploit, Third Party Advisory
- https://github.com/rapid7/metasploit-framework/pull/16807Exploit, Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-37393?
How severe is CVE-2022-37393?
How do I fix CVE-2022-37393?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-37388This vulnerability allows remote attackers to execute arbitr…7.8
- CVE-2022-37389This vulnerability allows remote attackers to execute arbitr…7.8
- CVE-2022-3739The WP Best Quiz WordPress plugin through 1.0 does not sanit…5.4
- CVE-2022-37390This vulnerability allows remote attackers to execute arbitr…7.8
- CVE-2022-37391This vulnerability allows remote attackers to execute arbitr…7.8
- CVE-2022-37392Improper Check for Unusual or Exceptional Conditions vulnera…5.3
- CVE-2022-37394An issue was discovered in OpenStack Nova before 23.2.2, 24.…3.3
- CVE-2022-37395A Huawei device has an input verification vulnerability. Suc…7.5
- CVE-2022-37396In JetBrains Rider before 2022.2 Trust and Open Project dial…7.8
- CVE-2022-37397An issue was discovered in the YugabyteDB 2.6.1 when using L…9.8
- CVE-2022-37398A stack-based buffer overflow vulnerability was found inside…8.8
- CVE-2022-3740An issue has been discovered in GitLab CE/EE affecting all v…4.9
Are you affected by CVE-2022-37393?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
