CVE-2025-23394

Published May 26, 2025

Last updated 2 months ago

Overview

Description
A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed cyrus-imapd allows escalation from cyrus to root.This issue affects openSUSE Tumbleweed cyrus-imapd before 3.8.4-2.1.
Source
meissner@suse.de
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

meissner@suse.de
CWE-61

Social media

Hype score
Not currently trending
  1. CVE-2025-23394 (CVSS:9.8, CRITICAL) is Awaiting Analysis. A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed cyrus-imapd allows escalation from cyrus t..https://t.co/iOxQ7z1C4A #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    31 May 2025

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2025-23394 (CVSS:9.8, CRITICAL) is Awaiting Analysis. A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed cyrus-imapd allows escalation from cyrus t..https://t.co/iOxQ7z1C4A #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    30 May 2025

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 【CVE-2025-23394】openSUSE Tumbleweedのメールサーバ向けコンポーネント「cyrus-imapd」にシンボリックリンク攻撃を悪用したroot権限昇格の脆弱性 https://t.co/RaiiTV9jhN @nikkeimatomeより

    @nikkeimatome

    30 May 2025

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 CVE-2025-23394 ⚠️🔴 CRITICAL (9.8) 🏢 SUSE - openSUSE Tumbleweed 🏗️ ? 🔗 https://t.co/n15HdEnFyC #CyberCron #VulnAlert #InfoSec https://t.co/KjlV0Ql28d

    @cybercronai

    27 May 2025

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2025-23394 A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed cyrus-imapd allows escalation from cyrus to root.This issue affects openSUSE Tumbleweed … https://t.co/SFWydH27AW

    @CVEnew

    26 May 2025

    601 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.