ZeroHour
The Recordpublished ()ingested

Zimbra bug causes alarm among researchers, CERTs after exploitation attempts

highExploit / PoC exploited in the wildimportance 60CVE-2024-45519

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-45519
Unauthenticated Command Execution in Synacor Zimbra Collaboration Suite (ZCS)

CVE-2024-45519 is an access-control weakness (CWE-284) in the postjournal service of Synacor Zimbra Collaboration Suite (ZCS) that allows an unauthenticated remote attacker to execute operating-system commands on the mail server. The postjournal service handles Zimbra's email journaling, and the flaw is reached by sending crafted mail/SMTP traffic to a vulnerable server, with no credentials or user interaction required. Successful exploitation gives the attacker command execution on the ZCS host, typically a foothold for stealing mailbox data and credentials, deploying webshells, or staging broader intrusion and ransomware activity. Any organization running ZCS is in scope, especially internet-exposed mail servers operated by enterprises, hosting/ISP providers, education, and government. Exploitation is confirmed in the wild: CISA added the flaw to the KEV catalog on 2024-10-03, and EPSS assigns a 99.9% probability of exploitation within 30 days (100th percentile), though no public PoC is known.

Do: Upgrade ZCS to the latest patch release per Synacor's advisory for this CVE, prioritizing internet-facing mail servers, since CISA's KEV required action is to apply vendor mitigations or discontinue use of the product if mitigations are unavailable. If patching cannot be done immediately, restrict untrusted network access to the postjournal/SMTP path and treat the host as presumptively compromised because exploitation is already in the wild. Check postjournal logs and unexpected child processes or dropped files on the server for signs of compromise, and re-verify after patching.

9.8100% KEV PoC
  • Synacor Zimbra Collaboration Suite (ZCS)
largetens of thousands of internet-exposed Zimbra mail servers (roughly 30,000-50,000 per public internet scans), plus many more firewalled deployments
Full article277 words · extracted from therecord.media · click to collapse

Multiple cybersecurity agencies in Europe warned about a vulnerability affecting Zimbra’s email product that researchers have confirmed is being exploited to spread malware.

Researchers at email security company Proofpoint said they began to see exploitation of the bug, tracked as CVE-2024-45519, on​​ September 28. Zimbra has released a patch, but several other experts said they are seeing mass targeting of the bug. 

Proofpoint said it saw emails spoofing Gmail “sent to bogus addresses in the CC fields in an attempt for Zimbra servers to parse and execute them as commands.” Those compromised servers also were used to host additional malware, the company said.

Greg Lesnewich, threat researcher at Proofpoint, said it is unclear who is  targeting the vulnerability and added that the exploitation is “geographically diverse and appears indiscriminate.”

“Defenders protecting Zimbra appliances should look out for odd CC or To addresses that look malformed or contain suspicious strings, as well as logs from the Zimbra server indicating outbound connections to remote IP addresses,” he said. 

National computer emergency response teams (CERTs) in Italy and Latvia have published warnings about the vulnerability while experts have released detailed proof of concept code. Other companies have published maps showing thousands of potentially vulnerable Zimbra instances across Europe

The vulnerability has not been added to the U.S. government-run National Vulnerability Database as of Wednesday. The Cybersecurity and Infrastructure Security Agency said it is aware of the CVE but did not have any comment.

Zimbra is a widely used email platform that is a frequent target for both nation-states and cyber criminals. 

Past vulnerabilities affecting Zimbra products were used to attack government agencies in Greece, Tunisia, Moldova, Vietnam and Pakistan.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/zimbra-email-vulnerability-exploitation