Report Incident
× Home Cybertech Africa 2023 2 DPO Rw-CSIRT Website About Rw-CSIRT Alerts Advisories About NCSA Documentation News & Events Topics Contact us Opportunities Privacy Policy

Alert: Active Exploitation of Critical Zimbra RCE Vulnerability (CVE-2024-45519)

A critical vulnerability in Zimbra Collaboration, known as CVE-2024-45519, has been identified in the Zimbra’s post-journal service. This flaw could allow for remote code execution (RCE), enabling attackers to execute arbitrary commands with the privileges of the Zimbra user. Consequently, they may be able to install programs or access, modify, or delete data.

 

Systems Affected:
 
Security Risks
Successful exploitation of this vulnerability in Zimbra can result in a complete compromise of the server. This allows attackers to execute malicious commands and gain access to sensitive data.
 
Recommended Actions
The National Cyber Security Authority (NCSA) recommends users and system administrators to:
  • Follow Zimbra's Security Advisories to lower the risk of potential exploits, protect systems, and ensure their security.
  • Apply the required and latest security updates as soon as possible.
        The released software version to upgrade to, are but are not limited to:
 
Before any update task, please ensure you have a recent backup that can easily be restored.
For further information and support, please contact the National Cyber Security Authority (NCSA) by email to rwcsirt@ncsa.gov.rw or call us on 9009.
 
References

03 October 2024

© 2024 National Cyber Security Authority