Zimbra 9.0/8.8.15 JVM Arg LPE (Priv Esc)
CVE-2023-24032 Published on June 15, 2023
In Zimbra Collaboration Suite through 9.0 and 8.8.15, an attacker (who has initial user access to a Zimbra server instance) can execute commands as root by passing one of JVM arguments, leading to local privilege escalation (LPE).
Products Associated with CVE-2023-24032
stack.watch emails you whenever new vulnerabilities are published in Zimbra Collaboration or Zimbra Collaboration Suite. Just hit a watch button to start following.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.