Aller au contenu

Fiche vulnérabilité

CVE-2024-27442 : faille élevée zimbra collaboration (CVSS 7.8)

Description

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The zmmailboxdmgr binary, a component of ZCS, is intended to be executed by the zimbra user with root privileges for specific mailbox operations. However, an attacker can escalate privileges from the zimbra user to root, because of improper handling of input arguments. An attacker can execute arbitrary commands with elevated privileges, leading to local privilege escalation.

En bref

Sévérité
Élevée (CVSS 7.8)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
12 août 2024
Dernière mise à jour
17 juin 2026

Produits concernés

  • zimbra collaboration

Références

Rechercher une autre vulnérabilité dans la base CVE