ZeroHour
Security Affairspublished ()ingested @securityaffairs

U.S. CISA adds Microsoft Partner Center and Synacor Zimbra Collaboration Suite flaws to its Known Exploited Vulnerabilities catalog

highExploit / PoC exploited in the wildimportance 60CVE-2023-34192CVE-2024-49035

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-34192
Authenticated XSS in Synacor Zimbra Collaboration Suite 8.8.15 Exploited in the Wild

CVE-2023-34192 is a critical (CVSS 3.1: 9.0) cross-site scripting (CWE-79) flaw in Synacor Zimbra Collaboration Suite (ZCS) 8.8.15. A remote, authenticated attacker submits a crafted script through the /h/autoSaveDraft endpoint (the autosave-draft handler of the web client), and because the vulnerability requires user interaction and changes scope, the script can execute in another user's browser session. By running code/actions in the security context of the victim's session, the attacker gains high-impact access to confidentiality, integrity, and availability (C:H/I:H/A:H per the CVSS vector). Organizations running ZCS 8.8.15 are affected. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-02-25 amid reported active exploitation, and EPSS is at 77.3% (100th percentile), though no public proof-of-concept is known.

Do: Upgrade ZCS 8.8.15 deployments to the latest available patch release per Synacor/Zimbra's instructions (or move to a supported release), as required by CISA's KEV listing and BOD 22-01 guidance for federal agencies. In the interim, restrict who can reach the /h/autoSaveDraft handler, review logs for suspicious POSTs to that endpoint and for injected drafts, and hunt for indicators of compromise such as unexpected mailbox rules or account activity.

9.077% KEV
  • Synacor Zimbra Collaboration Suite (ZCS) 8.8.15 (per the CVE description; no other ranges specified in the data)
largeon the order of tens of thousands of internet-exposed Zimbra servers (roughly 10k–100k affected deployments)
CVE-2024-49035
Unauthenticated Privilege Escalation in Microsoft Partner Center

An improper access-control flaw (CWE-269) in Microsoft's Partner Center portal at Partner.Microsoft.com allows an unauthenticated, remote attacker to elevate privileges over the network, earning a critical CVSS 3.1 score of 9.8. The flaw is triggered by network requests to the internet-facing portal that bypass access-control checks, requiring no credentials or user interaction. A successful attacker gains elevated privileges within Partner Center, the portal partners use to manage Microsoft cloud customer tenants and reseller relationships, potentially exposing partner and customer management functions. Any organization using Microsoft Partner Center — typically CSP partners, direct bill partners, and indirect resellers — is affected. The flaw is actively exploited: Microsoft addressed it in its November 2024 security fixes with exploitation seen in active attacks, and CISA added it to the KEV catalog on 2025-02-25.

Do: Partner Center is a Microsoft-managed cloud service, so no customer-side upgrade version applies — confirm with Microsoft that the service-side fix is in place, and federal agencies must follow BOD 22-01/KEV required actions (apply vendor mitigations or discontinue use). Review Entra ID sign-in logs and Partner Center audit logs for unauthenticated access, unexpected role or privilege changes, and anomalous app registrations or consent grants, and rotate credentials for affected partner accounts if compromise is suspected.

9.81% KEV
  • Microsoft Partner Center (partner.microsoft.com) Cloud service; no version ranges specified in the data (remediated service-side by Microsoft)
masshundreds of thousands of partner organizations (Microsoft's partner ecosystem is commonly cited at 400k+ partners); exact account/user counts undisclosed
Full article272 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini February 26, 2025

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Partner Center and Synacor Zimbra Collaboration Suite vulnerabilities to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added SonicWall SonicOS and Palo Alto PAN-OS vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog.

The two vulnerabilities are:

  • CVE-2023-34192 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
  • CVE-2024-49035 Microsoft Partner Center Improper Access Control Vulnerability

The first vulnerability, CVE-2023-34192 (CVSS score: 9.0), is a cross-site scripting (XSS) issue in Synacor ZCS. A remote authenticated attacker could exploit the vulnerability to execute arbitrary code via a crafted script to the /h/autoSaveDraft function. The vulnerability was addressed in July 2023 with version 8.8.15 Patch 40.

The second vulnerability, CVE-2024-49035 (CVSS score: 8.7), is an improper access control vulnerability in Microsoft Partner Center, an attacker could exploit the flaw to escalate privileges. Microsoft addressed the vulnerability with the release of Patch Tuesday security updates in November 2024.

“An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network.” reads the advisory published by Microsoft.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix this vulnerability by March 25, 2025.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/174664/security/u-s-cisa-adds-microsoft-partner-center-and-synacor-zimbra-collaboration-suite-flaws-to-its-known-exploited-vulnerabilities-catalog.html