Zimbra zmslapd arbitrary module load
Vulnerability Description
Zimbra's sudo configuration permits the zimbra user to execute the zmslapd binary as root with arbitrary parameters. As part of its intended functionality, zmslapd can load a user-defined configuration file, which includes plugins in the form of .so files, which also execute as root.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-37393
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Darren Martyn discovered and disclosed this vulnerability
References
Affected Vendor
Synacor
View all reports →