CVE-2024-45519
Synacor Zimbra Collaboration Suite (ZCS) Command Execution Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 24 October 2024). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 sometimes allows unauthenticated users to execute commands.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 99.91% probability · 100th percentile
- CISA KEV
- Listed 3 October 2024 · due 24 October 2024
- Weakness
- CWE-78
- Affected
- synacor/zimbra collaboration suite
- Source
- cve@mitre.org
CISA notes
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories ; https://nvd.nist.gov/vuln/detail/CVE-2024-45519
References
- https://wiki.zimbra.com/wiki/Security_CenterRelease Notes
- https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.9#Security_FixesRelease Notes
- https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.1#Security_FixesRelease Notes
- https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P46#Security_FixesRelease Notes
- https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P41#Security_FixesRelease Notes
- https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_PolicyNot Applicable
- https://blog.projectdiscovery.io/zimbra-remote-code-execution/Exploit
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-45519US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.