CVE-2024-45519
About
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 sometimes allows unauthenticated users to execute commands.
Rainforest analyst review
Zimbra Collaboration's postjournal service, which handles journaling of email, fails to properly sanitize input before it reaches a system command, so an unauthenticated attacker can inject operating-system commands that execute on the mail server. The trigger is reachable by sending crafted SMTP traffic, meaning an attacker who can deliver mail to a vulnerable server can, under the right conditions, run commands on it without any credentials or interaction.
Zimbra is a widely deployed open-source email and collaboration platform, and mail servers are internet-facing by necessity, which puts a large exposed population directly within reach. Zimbra has a long track record of being targeted, and this flaw was exploited in the wild almost immediately after disclosure, with mass-exploitation attempts observed dropping web shells within days of the patch. Update to the fixed builds (8.8.15 Patch 46, 9.0.0 Patch 41, 10.0.9, or 10.1.1) without delay, and where postjournal is not required, confirm it is disabled. Because exploitation began so quickly, treat exposed servers as possibly already compromised and hunt for planted web shells and anomalous outbound activity rather than relying on the patch alone.
References
- https://wiki.zimbra.com/wiki/Security_Center
- https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.9#Security_Fixes
- https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.1#Security_Fixes
- https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P46#Security_Fixes
- https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P41#Security_Fixes
- https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy
- https://blog.projectdiscovery.io/zimbra-remote-code-execution/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-45519
Related CVEs
Frequently asked questions
What is CVE-2024-45519?
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 sometimes allows unauthenticated users to execute commands.
How severe is CVE-2024-45519?
CVE-2024-45519 carries a CVSS 3.1 base score of 10, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 100 out of 100, in the critical band.
How is CVE-2024-45519 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.
Which products are affected by CVE-2024-45519?
Public advisories list the following as affected: zimbra collaboration suite. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2024-45519?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
