CVE-2024-45519
synacor zimbra collaboration suite
Published 2 Oct 2024 · updated 17 Jun 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 3 Oct 2024, with a remediation deadline of 24 Oct 2024 for US federal agencies.
Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 sometimes allows unauthenticated users to execute commands.
References
- wiki.zimbra.com/wiki/Security_Center · Release Notes
- wiki.zimbra.com/wiki/Zimbra_Releases/10.0.9#Security_Fixes · Release Notes
- wiki.zimbra.com/wiki/Zimbra_Releases/10.1.1#Security_Fixes · Release Notes
- wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P46#Security_Fixes · Release Notes
- wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P41#Security_Fixes · Release Notes
- wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy · Not Applicable
- blog.projectdiscovery.io/zimbra-remote-code-execution/ · Exploit
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-45519 · US Government Resource