← back
CVE-2022-37393CWE-284

Zimbra zmslapd arbitrary module load

18Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 1.7%
from disclosure to weapon0 days
Published on NVDAug 16
metasploitOct 27
exploitation probability
1.7%top 24% of all CVEs
observed exploitation
nono source reports it
Zimbra's sudo configuration permits the zimbra user to execute the zmslapd binary as root with arbitrary parameters. As part of its intended functionality, zmslapd can load a user-defined configuration file, which includes plugins in the form of .so files, which also execute as root.
Affected products
Synacor · Zimbra Server