
Zimbra releases an update patch to fix a critical vulnerability that allows hackers to execute malicious code without clicking.
Information: Previously referred to as the Zimbra Collaboration Suite (ZCS), Zimbra is a comprehensive communication software solution that encompasses an email server and a web client. This suite offers a wide range of functionalities, including messaging, email, file sharing, calendar management, and task tracking.
Incident : Last week, Zimbra released patches for a critical stored cross-site scripting (XSS) security vulnerability affecting the Classic Web Client (Classic UI). This vulnerability could lead to code execution when opening an email.
Zimbra stated that the update resolves a security issue in the Classic Web Client where a specially crafted email could execute malicious code upon opening. If exploited, this vulnerability could grant unauthorized access to mailbox information, session data, or account settings.
Zimbra refrained from disclosing specific details about the flaw, which has not yet been assigned a CVE identifier. However, it strongly advised all customers utilizing the Classic Web Client to promptly update their deployments.
The bug was resolved in Zimbra version 10.1.19, released on July 7. Customers upgrading from ZCS versions 10.0.x, 9.0.x, or 8.8.15 should update the SNMP mitigation and reapply it after the upgrade has been completed.
Zimbra strongly recommends that all customers upgrade to ZCS v10.1.19 to ensure they have received the latest security patches, bug fixes, and enhancements.
The vulnerability was reported by Google Threat Analysis Group (GTIG), which typically identifies security defects targeted by state-sponsored groups and commercial spyware vendors.
Recommendation :
•Customers upgrading from ZCS 10.1.x: No additional action is required. If the SNMP mitigation has already been applied on your existing 10.1.x deployment, it will remain effective after upgrading to ZCS v10.1.19.
•Customers upgrading from ZCS 10.0.x, 9.0.x, or 8.8.15: The SNMP mitigation must be updated and reapplied after upgrading to ZCS v10.1.19.
References :
•https://www.securityweek.com/zimbra-patches-critical-code-execution-vulnerability/
•https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.19
•https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.0/patch_installation