Skip to content
COOEY

EXPOSURES › CVE-2024-45519

CVE-2024-45519

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-10-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-45519 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatchedransomware

Synacor ZCS unauthenticated RCE in postjournal service actively exploited by threat actors.

An unauthenticated command execution vulnerability in Synacor's Zimbra postjournal service allows attackers to execute arbitrary commands without authentication, directly enabling remote compromise of collaboration infrastructure. This failure represents a chronic vulnerability management lapse where critical flaws persist long enough for active exploitation, posing severe data exfiltration and ransomware risks to DIB organizations relying on ZCS.

Shame score — Active exploitation of a critical unauthenticated RCE in a widely deployed collaboration platform indicates a systemic failure to patch known vulnerabilities promptly.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Synacor Zimbra Collaboration Suite (ZCS) contains an unspecified vulnerability in the postjournal service that may allow an unauthenticated user to execute commands.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.