Due to an issue with incorrect sudo permissions, Zimbra Collaboration Suite (ZCS) suffers from a local privilege escalation issue in versions 9.0.0 and prior, where the 'zimbra' user can effectively coerce postfix into running arbitrary commands as 'root'.
The product does not drop privileges before passing control of a resource to an actor that does not have those privileges.
Link | Tags |
---|---|
https://twitter.com/ldsopreload/status/1580539318879547392 | third party advisory |
https://github.com/rapid7/metasploit-framework/pull/17141 | patch exploit third party advisory issue tracking |
http://packetstormsecurity.com/files/169430/Zimbra-Privilege-Escalation.html | third party advisory vdb entry exploit |