Critical Zimbra RCE flaw exploited to backdoor servers using emails
ID: 471c3792-937f-51d1-b160-1f62c8948945
STIX ID: report--471c3792-937f-51d1-b160-1f62c8948945
Feed Name: Bleeping Computer
Active exploitation of Zimbra remote code execution vulnerability CVE-2024-45519 has been observed: attackers send specially crafted SMTP emails (CC field) that trigger command execution in the postjournal service, drop a base64-decoded webshell that listens for a JSESSIONID cookie and executes base64-encoded commands from a JACTION cookie, and can download/execute files; Proofpoint and HarfangLab reported mass-exploitation shortly after a public PoC and a ready-to-use exploit were published—administrators are urged to apply Zimbra patches (specified versions) or disable postjournal and secure mynetworks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
