ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

CISA Adds Microsoft and Zimbra Flaws to KEV Catalog Amid Active Exploitation

criticalExploit / PoC exploited in the wildimportance 60CVE-2024-49035CVE-2023-34192

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-34192
Authenticated XSS in Synacor Zimbra Collaboration Suite 8.8.15 Exploited in the Wild

CVE-2023-34192 is a critical (CVSS 3.1: 9.0) cross-site scripting (CWE-79) flaw in Synacor Zimbra Collaboration Suite (ZCS) 8.8.15. A remote, authenticated attacker submits a crafted script through the /h/autoSaveDraft endpoint (the autosave-draft handler of the web client), and because the vulnerability requires user interaction and changes scope, the script can execute in another user's browser session. By running code/actions in the security context of the victim's session, the attacker gains high-impact access to confidentiality, integrity, and availability (C:H/I:H/A:H per the CVSS vector). Organizations running ZCS 8.8.15 are affected. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-02-25 amid reported active exploitation, and EPSS is at 77.3% (100th percentile), though no public proof-of-concept is known.

Do: Upgrade ZCS 8.8.15 deployments to the latest available patch release per Synacor/Zimbra's instructions (or move to a supported release), as required by CISA's KEV listing and BOD 22-01 guidance for federal agencies. In the interim, restrict who can reach the /h/autoSaveDraft handler, review logs for suspicious POSTs to that endpoint and for injected drafts, and hunt for indicators of compromise such as unexpected mailbox rules or account activity.

9.077% KEV
  • Synacor Zimbra Collaboration Suite (ZCS) 8.8.15 (per the CVE description; no other ranges specified in the data)
largeon the order of tens of thousands of internet-exposed Zimbra servers (roughly 10k–100k affected deployments)
CVE-2024-49035
Unauthenticated Privilege Escalation in Microsoft Partner Center

An improper access-control flaw (CWE-269) in Microsoft's Partner Center portal at Partner.Microsoft.com allows an unauthenticated, remote attacker to elevate privileges over the network, earning a critical CVSS 3.1 score of 9.8. The flaw is triggered by network requests to the internet-facing portal that bypass access-control checks, requiring no credentials or user interaction. A successful attacker gains elevated privileges within Partner Center, the portal partners use to manage Microsoft cloud customer tenants and reseller relationships, potentially exposing partner and customer management functions. Any organization using Microsoft Partner Center — typically CSP partners, direct bill partners, and indirect resellers — is affected. The flaw is actively exploited: Microsoft addressed it in its November 2024 security fixes with exploitation seen in active attacks, and CISA added it to the KEV catalog on 2025-02-25.

Do: Partner Center is a Microsoft-managed cloud service, so no customer-side upgrade version applies — confirm with Microsoft that the service-side fix is in place, and federal agencies must follow BOD 22-01/KEV required actions (apply vendor mitigations or discontinue use). Review Entra ID sign-in logs and Partner Center audit logs for unauthenticated access, unexpected role or privilege changes, and anomalous app registrations or consent grants, and rotate credentials for affected partner accounts if compromise is suspected.

9.81% KEV
  • Microsoft Partner Center (partner.microsoft.com) Cloud service; no version ranges specified in the data (remediated service-side by Microsoft)
masshundreds of thousands of partner organizations (Microsoft's partner ecosystem is commonly cited at 400k+ partners); exact account/user counts undisclosed
Full article242 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananFeb 26, 2025Enterprise Security / Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday placed two security flaws impacting Microsoft Partner Center and Synacor Zimbra Collaboration Suite (ZCS) to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.

The vulnerabilities in question are as follows -

  • CVE-2024-49035 (CVSS score: 8.7) - An improper access control vulnerability in Microsoft Partner Center that allows an attacker to escalate privileges. (Fixed in November 2024)
  • CVE-2023-34192 (CVSS score: 9.0) - A cross-site scripting (XSS) vulnerability in Synacor ZCS that allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function. (Fixed in July 2023 with version 8.8.15 Patch 40)

Last year, Microsoft acknowledged that CVE-2024-49035 had been exploited in the wild, but did not reveal any additional details on how it was weaponized in real-world attacks. There are currently no public reports about in-the-wild abuse of CVE-2023-34192.

In light of the development, Federal Civilian Executive Branch (FCEB) agencies are mandated to apply the necessary updates by March 18, 2025, to secure their networks.

The development comes a day after CISA added two security flaws impacting Adobe ColdFusion and Oracle Agile Product Lifecycle Management (PLM) to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/02/cisa-adds-microsoft-and-zimbra-flaws-to.html