Executive brief
Zimbra Collaboration, a widely used enterprise email and collaboration platform, is vulnerable to a security flaw that allows remote attackers to execute unauthorized commands. By exploiting how the system processes data, an attacker could potentially gain full control over the server, leading to the theft of sensitive emails, data breaches, or disruption of business communications. Organizations using versions older than 8.7.0 should upgrade immediately to protect their infrastructure.
Technical details
Zimbra Collaboration (ZCS) versions prior to 8.7.0 are vulnerable to an untrusted data deserialization flaw (CWE-502). The vulnerability exists in unspecified vectors within the application's handling of serialized objects. A remote, unauthenticated attacker can exploit this by sending specially crafted data to the server, which, when processed, can lead to arbitrary code execution or unauthorized access to sensitive information. The issue is tracked internally by Zimbra as bug 102276 and was addressed in the 8.7.0 General Availability release.
Affected products
- Zimbra Zimbra Collaboration before 8.7.0
Timeline
- 2016-07-01: patched: Fixed in Zimbra Collaboration 8.7.0 GA release
- 2017-01-18: disclosed: NVD publication date