ZeroHour

CVE-2019-9670

KEV PoC ×3large

XML External Entity (XXE) Injection in Synacor Zimbra Collaboration Suite (ZCS)

CISA: Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference

CVSS 3.1
9.8 critical
EPSS
100%p100
Published
()
KEV added
AI analysis

Synacor Zimbra Collaboration Suite (ZCS) contains an improper restriction of XML external entity (XXE) vulnerability (CWE-611) in its mailboxd component, meaning XML parsing accepts external entity references that the parser should restrict. By submitting crafted XML that ZCS parses in mailboxd, an attacker can typically direct the server to fetch external entities, potentially disclosing local files or issuing server-side requests; the available data does not specify authentication requirements or exact affected version ranges. Organizations running Synacor Zimbra Collaboration Suite are affected. The flaw is confirmed as exploited in the wild: CISA added CVE-2019-9670 to the Known Exploited Vulnerabilities catalog on 2022-01-10, and EPSS assigns a 100% probability of exploitation within 30 days; no public PoC is listed and ransomware association is listed as unknown.

What to do: Apply updates per Synacor/Zimbra instructions, as required by the CISA KEV catalog; because no fixed version numbers are provided in the available data, administrators of all ZCS deployments should consult current vendor advisories and patch promptly. As interim mitigation, restrict or disable external entity resolution in XML processing and limit exposure of mailboxd-facing services. Check mailboxd logs and outbound network activity for signs of entity resolution or unexpected connections, and prioritize this fix given the 2022-01-10 KEV listing and 100% EPSS score.

Affected
Synacor Zimbra Collaboration Suite (ZCS)
Estimated exposure
largetens of thousands of internet-exposed ZCS servers (estimate; user impact likely higher) — Zimbra is one of the most widely deployed self-hosted email/collaboration platforms, and public internet-wide scans have repeatedly shown tens of thousands of exposed Zimbra instances; this is an order-of-magnitude estimate from deployment…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml.

CISA Known Exploited Vulnerability
Affected
Synacor Zimbra Collaboration Suite (ZCS)
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
synacor
Products
zimbra collaboration suite
Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news