Synacor Zimbra Collaboration Command Execution Vulnerability
What is the Vulnerability? | Attackers are actively exploiting CVE-2024-45519, a critical Zimbra vulnerability that allows attackers to execute arbitrary commands on vulnerable systems. CVE-2024-45519 is a vulnerability in the postjournal service used for recording email communications. This OS command injection flaw can be exploited without authentication and successful exploitation can lead to unauthorized access, privilege escalation, and potential compromise of the affected system's integrity and confidentiality. |
What is the recommended Mitigation? | Zimbra has released a patch for CVE-2024-45519. Organizations that haven’t implemented the latest patch are advised to do so immediately. https://blog.zimbra.com/2024/10/zimbra-cve-2024-45519-vulnerability-stay-secure-by-updating/ |
What FortiGuard Coverage is available? |
|
Outbreak Alert
Threat Actors are exploiting a recently fixed RCE vulnerability in Zimbra email servers, which can be exploited just by sending specially crafted emails to the SMTP server.
Additional Resources
Patch Release: Zimbra Blog
Zimbra - Remote Command Execution (CVE-2024-45519) (projectdiscovery.io)
Virus | FortiGuard Labs
Intrusion Prevention | FortiGuard Labs