Security researchers warn of mass exploitation of a critical vulnerability (CVE-2024-45519) affecting Zimbra mail servers. The vulnerability allows attackers to execute remote code, potentially leading to unauthorized access, privilege escalation, and system compromise. Project Discovery reports that attacks utilize base64 strings in CC fields, which are then parsed and executed by vulnerable Zimbra servers.
"Patch yesterday" is the advice from infosec researchers as the latest critical vulnerability affecting Zimbra mail servers is now being mass-exploited.
"Successful exploitation can lead to unauthorized access, privilege escalation, and potential compromise of the affected system's integrity and confidentiality," the researchers said. Its PoC exploit worked on ports 10027 and 25, and after some teething issues, it was proven to work remotely too, as evidenced by the exploit attempts since.on Tuesday the attacker, or attackers, is unknown, and"for unknown reasons" the same server used to send the malicious emails is also hosting the second-stage payload.
Like many of the recent vulnerabilities reported to the company behind the business email and collaboration platform, it has not yet been assigned a severity score.
CVE-2024-45519 Zimbra Vulnerability Exploitation Remote Code Execution
Singapore Latest News, Singapore Headlines
Similar News:You can also read news stories similar to this one that we have collected from other news sources.
'Patch yesterday': Zimbra mail servers under siege through RCE vulnAttacks began the day after public disclosure
Read more »
Baldur’s Gate 3 Patch 7 patch notes adds almost too much content The full Baldur's Gate 3 Patch 7 patch notes are here, offering a massive content update for the beloved RPG game.
Read more »
First ever 'neep patch' opening near Glasgow to revive much loved Scots Halloween traditionForget the pumpkins - there's a neep patch coming soon to Chatelherault Country Park, promising to revive the tradition of carving 'tumshie lanterns' that Scots of a certain age will remember!
Read more »
Why the A6 was closed for four hours in Walton-le-Dale yesterdayThe roundabout with Hennel Lane was shut due to the police incident
Read more »
Black Ops 6 beta patch notes today heavily nerf Jackal PDW SMG, increase level capTreyarch's latest Black Ops 6 patch notes today have given the Jackal PDW a massive nerf and raised the level cap to 30.
Read more »
Helldivers 2 CCO teases exciting buff for “next patch” as fans rejoiceHelldivers 2 is back with the most recent update, and the CCO has teased another exciting buff for the 'next patch'.
Read more »