Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Email Security

Critical Zimbra Vulnerability Exploited One Day After PoC Release

A critical-severity vulnerability in Zimbra has been exploited in the wild to deploy a web shell on vulnerable servers.

Phishing

Security researchers have raised the alarm on the in-the-wild exploitation of a critical-severity vulnerability in the popular email and collaboration platform Zimbra.

Tracked as CVE-2024-45519, the security defect allows attackers to execute commands on a vulnerable server, without authentication.

Zimbra versions 9.0.0 Patch 41, 10.0.9, 10.1.1, and 8.8.15 Patch 46 fix “a security vulnerability in the postjournal service which may allow unauthenticated users to execute commands,” Synacor-owned Zimbra said.

While the company did not share specific details on the bug and the vulnerability has yet to be added to NIST’s National Vulnerability Database (NVD), ProjectDiscovery last week released technical information on the flaw, along with a PoC exploit.

The underlying issue, ProjectDiscovery explained, was the lack of sanitization of user-provided input, allowing attackers to craft SMTP messages to inject commands on the postjournal service.

While the service is disabled by default, attackers could exploit the flaw remotely on servers that have it enabled, if the attack originates from within an allowed network range.

Advertisement. Scroll to continue reading.

The first exploitation attempts targeting CVE-2024-45519 were seen on September 28, one day after ProjectDiscovery published its analysis of the vulnerability.

“The emails spoofing Gmail were sent to bogus addresses in the CC fields in an attempt for Zimbra servers to parse and execute them as commands. The addresses contained base64 strings that are executed with the sh utility,” cybersecurity firm Proofpoint revealed on Tuesday.

The company observed emails using multiple CC’d addresses meant to deploy a web shell on the affected Zimbra servers. The web shell supports command execution and payload deployment.

HarfangLab security researcher Ivan Kwiatkowski on Tuesday warned that an IP address was seen delivering malicious emails and payloads in mass-exploitation attempts of CVE-2024-45519.

Proofpoint noted that the attackers have been using the same server for the delivery of both exploit emails and second-stage payloads, but did not attribute the activity to a known threat actor.

Related: Organizations Warned of Exploited SAP, Gpac and D-Link Vulnerabilities

Related: Microsoft Says Recent Windows Vulnerability Exploited as Zero-Day

Related: Windows Event Log Vulnerabilities Could Be Exploited to Blind Security Products

Related: Jetty Flaw Can Be Exploited to Inflate Target’s Cloud Bill, Cause Disruption

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we break down why email-layer defenses alone can't keep pace with the modern phishing ecosystem, how agentic AI is changing the capacity equation for security teams, and more.

Register

This year's summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments. Interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments.

Register

People on the Move

Fable Security has appointed Jacob Berry as Chief Information Security Officer.

iCOUNTER has named Ali Waezzadah as Chief Information Security Officer.

Roger Hale has joined 1Kosmos as Chief Information Security Officer.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.