LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-9670: Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference

RBRecent Breaches Vulnerability Intelligence·Jan 10, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jul 10, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-9670 to its Known Exploited Vulnerabilities catalog on Jan 10, 2022, with a federal patch deadline of Jul 10, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Synacor Zimbra Collaboration Suite (ZCS) contains an improper restriction of XML external entity (XXE) vulnerability in the mailboxd component.

CVE-2019-9670 is an XML external entity (XXE) vulnerability in the mailboxd component of Synacor Zimbra Collaboration Suite (ZCS). It stems from improper restriction of XML external entity references, allowing crafted XML input to be processed in unsafe ways. For IT and security teams running Zimbra, this matters because mailboxd is central to mail and collaboration services; successful abuse can lead to unauthorized data access or further compromise of the messaging platform, so timely identification and remediation are essential.

How it works

This flaw belongs to CWE-611: Improper Restriction of XML External Entity Reference. In products that parse XML, the parser may be configured to resolve external entities—references that can point to local files, internal network resources, or other data sources. When restriction is missing or incomplete, an attacker who can supply XML to the vulnerable component (here, mailboxd) may cause the parser to retrieve or disclose information that should remain inaccessible.

Abuse typically involves sending specially formed XML that triggers entity resolution. The exact request paths, payloads, or resulting impact depend on the Zimbra configuration and must be confirmed against the vendor advisory; defenders should treat any untrusted XML input to mailboxd as a potential vector for this class of attack without assuming specific exploit mechanics.

Am I affected? How to find it in your systems

Synacor Zimbra Collaboration Suite is commonly deployed as an on-premises or self-hosted email and collaboration platform. mailboxd is a core service process, so any ZCS installation that exposes or uses this component should be inventoried.

If public detail on exact affected builds is limited in your environment documentation, treat all unpatched ZCS deployments as potentially vulnerable until verified against the official advisory.

How to remediate

Patch first. Apply the updates provided by the vendor for Synacor Zimbra Collaboration Suite exactly as described in the official advisory for CVE-2019-9670. CISA’s required action is to apply updates per vendor instructions; follow those steps, including any prerequisite or post-update service restarts.

If you can't patch immediately

Until the vendor update can be applied, reduce risk with compensating controls tailored to XXE and mail-server exposure.

These measures lower likelihood and impact but are not a substitute for the vendor patch.

If your data may have been exposed

Actively exploited vulnerabilities can lead to unauthorized access or data exposure even when ransomware use is not documented for this CVE. If you suspect compromise, follow your incident-response process: isolate affected hosts, preserve logs, and assess what mailbox or configuration data may have been reachable. As a further check, you can run a free exposure scan of your email addresses against known breach datasets to see whether credentials or related information have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSynacor · Zimbra Collaboration Suite (ZCS)
WeaknessCWE-611
Added to CISA KEVJan 10, 2022
Federal patch deadlineJul 10, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities