In Zimbra Collaboration Suite through 9.0 and 8.8.15, an attacker (who has initial user access to a Zimbra server instance) can execute commands as root by passing one of JVM arguments, leading to local privilege escalation (LPE).
Advisories
Source ID Title
EUVD EUVD EUVD-2023-28096 In Zimbra Collaboration Suite through 9.0 and 8.8.15, an attacker (who has initial user access to a Zimbra server instance) can execute commands as root by passing one of JVM arguments, leading to local privilege escalation (LPE).
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00071}

epss

{'score': 0.00073}


Wed, 18 Dec 2024 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-12-18T16:25:25.188Z

Reserved: 2023-01-20T00:00:00

Link: CVE-2023-24032

cve-icon Vulnrichment

Updated: 2024-08-02T10:49:08.930Z

cve-icon NVD

Status : Modified

Published: 2023-06-15T21:15:09.593

Modified: 2024-11-21T07:47:17.837

Link: CVE-2023-24032

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.