Junglewise Threat Intelligence

CVE-2019-9670: Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference

CVE-2019-9670 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-01-10

Technologies: Synacor Zimbra Collaboration Suite, Synacor Zimbra Collaboration Suite (ZCS). Vendors: Synacor.

Executive brief

The mailboxd component in Synacor Zimbra Collaboration Suite (ZCS) contains an XML External Entity (XXE) injection vulnerability. The flaw is specifically present in the Autodiscover/Autodiscover.xml handler, allowing remote attackers to access sensitive information or potentially achieve further compromise.

Affected products

  • Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10

Timeline

  • 2019-03-11: disclosed: Initial CVE assignment/publication date based on CVE ID year and external references.
  • 2022-01-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2022-01-10: advisory: NVD publication date.
  • 2022-01-10: exploited: Confirmed as exploited in the wild by CISA.

Related threats