Zimbra RCE Vuln Under Attack Needs Immediate Patching
ID: e6ee9418-14eb-53ea-a07f-871b595949a0
STIX ID: report--e6ee9418-14eb-53ea-a07f-871b595949a0
Feed Name: Dark Reading
Active exploitation of a critical Zimbra remote code execution (CVE-2024-45519) in the postjournal service is ongoing: attackers send spoofed emails containing base64-encoded payloads in the CC field to induce command injection, install web shells that accept commands via cookies, and run arbitrary code. Security vendors (Proofpoint, ProjectDiscovery, HarfangLab) observed exploitation beginning Sept. 28, published indicators (including an attacker IP) and a proof-of-concept, and Zimbra has released patches — administrators are urged to apply them immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
