Security readout for executives and security teams
Plain-English summary
This is a critical Zimbra Collaboration flaw that can let unauthenticated attackers run commands through the postjournal service. For an email platform, that can mean mailbox compromise, service disruption, and a foothold into connected infrastructure. CISA lists it as known exploited, so exposed unpatched systems should be treated as urgent.
Executive priority
Treat this as an emergency remediation item for any Zimbra environment. It is remotely reachable, unauthenticated, critical severity, and listed by CISA as known exploited. Patch exposed systems immediately and require incident review for any system that was vulnerable while reachable.
Technical view
CVE-2024-45519 is a CWE-78 command injection issue in Zimbra Collaboration postjournal. Affected versions are before 8.8.15 Patch 46, 9.0.0 Patch 41, 10.0.9, and 10.1.1. The CVSS 3.1 score is 10.0, with network attack vector, no privileges, no user interaction, and high confidentiality, integrity, and availability impact.
Likely exposure
Organizations running Zimbra Collaboration below the fixed patch levels are potentially exposed, especially if ZCS services are reachable from the internet or untrusted networks. The supplied affected CPE data is incomplete, so validation should rely on deployed Zimbra version and patch level rather than vendor/product fields in the CVE feed.
Exploitation context
Active exploitation is supported by CISA KEV listing for CVE-2024-45519. ProjectDiscovery also published public RCE research. The provided sources do not establish exact attacker volume, targeting patterns, or whether exploitation requires postjournal to be enabled in every deployment.
Researcher notes
The CVE feed identifies Zimbra versions and CWE-78 but has incomplete affected product metadata. Research should focus on confirming postjournal exposure, patch state, and historical signs of command execution. Do not assume safe status from CPE matching alone.
Mitigation direction
- Upgrade ZCS 8.8.15 to Patch 46 or later.
- Upgrade ZCS 9.0.0 to Patch 41 or later.
- Upgrade ZCS 10.0 to 10.0.9 or later.
- Upgrade ZCS 10.1 to 10.1.1 or later.
- Follow Zimbra guidance for any compensating controls if patching is delayed.
- Review CISA KEV deadlines and prioritize exposed systems first.
Validation and detection
- Inventory all Zimbra Collaboration servers and record exact patch levels.
- Compare each system against the fixed versions listed by Zimbra.
- Confirm whether ZCS services are reachable from internet or untrusted networks.
- Review ZCS and system logs for suspicious command execution indicators.
- Verify patch deployment after maintenance through version checks.
- Track any vendor advisories for updated detection or remediation guidance.
Public sources used
Michael Williams reviewed this cited source version on .
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-78: Command execution behavior lookup
Command injection weaknesses can lead defenders to review execution techniques and command interpreter telemetry. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupCVE-2024-45519 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Critical
- CVSS
- 10 (3.1)
- Known Exploited
- Yes
- Published
Vector: CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:C/UI:N
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CISA KEV status
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:C/UI:N3.96Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
10CriticalVector: CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:C/UI:N
Source materials
- CVE List V5 sourceCVE List V5
- https://wiki.zimbra.com/wiki/Security_CenterCVE reference
- https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_PolicyCVE reference
- https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.1#Security_FixesCVE reference
- https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.9#Security_FixesCVE reference
- https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P41#Security_FixesCVE reference
- https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P46#Security_FixesCVE reference
- https://blog.projectdiscovery.io/zimbra-remote-code-execution/CVE reference · exploit
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-45519CVE reference · government-resource
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
