Loading video...
Video Failed to Load
⚠️ We've confirmed critical CVE-2024-45519 in Zimbra! SMTP-based vulnerability in postjournal service allows unauthenticated attackers to inject commands under zimbra user. ✅ Update your software ASAP to avoid exploitation!
84,313 views • 1 year ago •via X (Twitter)
6 Comments

Threath Hunting1 year ago
Any poc public please🙏

yashar Alinejad 🇮🇱1 year ago
Are there public POCs available yet?

nani smmith1 year ago
Even there is no clear explanation to understand it in the wild, that is frustrated😣

Null1 year ago
make it more detail

Sigtrap1 year ago
Who is vulnerable? Just Zimbra or even Carbonio? Does zimbraArchiveAccount need to be turned on?

[email protected] / PurpleLabs / EDRmetry1 year ago
If you can't update or still waiting for an update, use bpftrace as a system-level virtual patch to kill child procs invoked by parent's execve()
