正在加载视频...
视频加载失败
⚠️ We've confirmed critical CVE-2024-45519 in Zimbra! SMTP-based vulnerability in postjournal service allows unauthenticated attackers to inject commands under zimbra user. ✅ Update your software ASAP to avoid exploitation!
6 条评论

Threath Hunting1 年前
Any poc public please🙏

yashar Alinejad 🇮🇱1 年前
Are there public POCs available yet?

nani smmith1 年前
Even there is no clear explanation to understand it in the wild, that is frustrated😣

Null1 年前
make it more detail

Sigtrap1 年前
Who is vulnerable? Just Zimbra or even Carbonio? Does zimbraArchiveAccount need to be turned on?

[email protected] / PurpleLabs / EDRmetry1 年前
If you can't update or still waiting for an update, use bpftrace as a system-level virtual patch to kill child procs invoked by parent's execve()
