EXPOSURES › CVE-2024-45519
CVE-2024-45519
HIGH ⌖ ON CISA KEV · EXPLOITEDSynacor ZCS unauthenticated RCE in postjournal service actively exploited by threat actors.
An unauthenticated command execution vulnerability in Synacor's Zimbra postjournal service allows attackers to execute arbitrary commands without authentication, directly enabling remote compromise of collaboration infrastructure. This failure represents a chronic vulnerability management lapse where critical flaws persist long enough for active exploitation, posing severe data exfiltration and ransomware risks to DIB organizations relying on ZCS.
Shame score — Active exploitation of a critical unauthenticated RCE in a widely deployed collaboration platform indicates a systemic failure to patch known vulnerabilities promptly.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Synacor Zimbra Collaboration Suite (ZCS) contains an unspecified vulnerability in the postjournal service that may allow an unauthenticated user to execute commands.