Junglewise Threat Intelligence

CVE-2024-45519: Synacor Zimbra Collaboration Suite (ZCS) Command Execution Vulnerability

CVE-2024-45519 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-10-03

Technologies: Synacor Zimbra Collaboration Suite (ZCS). Vendors: Synacor.

Executive brief

The postjournal service in Synacor Zimbra Collaboration Suite (ZCS) contains a vulnerability that allows unauthenticated remote attackers to execute arbitrary commands. This issue stems from improper neutralization of special elements used in an OS command.

Affected products

  • Synacor Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1

Timeline

  • 2024-10-03: disclosed
  • 2024-10-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • exploited: Reported as exploited in the wild.

Related threats