Zimbra RCE Vulnerability Under Active Attack
ID: 2505bab5-f526-5e54-8eb1-b80ef8866712
STIX ID: report--2505bab5-f526-5e54-8eb1-b80ef8866712
Feed Name: Cyble Blog
A critical unauthenticated RCE (CVE-2024-45519) in Zimbra's postjournal service is being actively exploited via specially crafted SMTP messages (port 10027 and, when enabled, port 25), with proofs-of-concept and observed webshell deployments; administrators are urged to patch to fixed Zimbra versions, disable postjournal if unused, and restrict mynetworks. Indicators include an identified malicious source IP (79.124.49.86) and a webshell path (/jetty/webapps/zimbraAdmin/public/jsp/zimbraConfig.jsp).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
