High
Zimbra, XSS, RCE, webmail, Classic Web Client, email security

A Crafted Email Is Enough to Run Code in Zimbra Users' Sessions
Zimbra is urging customers to patch a critical flaw in its Classic Web Client, a stored cross-site scripting bug that lets a crafted email execute code in a victim's session. Webmail has a long history of being hit fast.
Zimbra is urging customers to apply updates for a critical vulnerability in its Classic Web Client, a stored cross-site scripting flaw that can lead to arbitrary code execution inside a user's session, as reported by The Hacker News.
The delivery mechanism is what makes this dangerous. The attack arrives as a crafted email, so a target does not need to click a suspicious link or download a file, only to open or view the message in the affected client. The victim's active, authenticated session becomes the place the attacker's code runs.
Webmail platforms are a recurring favorite for attackers, and Zimbra in particular has been targeted repeatedly, because a mail server sits on a rich trove of correspondence and often on the credentials that unlock the rest of an organization. A flaw that triggers on viewing a message shortens the path from inbox to intrusion considerably.
The fix is to update to the patched version without waiting, and to watch for unusual mailbox activity in the meantime. Where an email itself can carry the exploit, patch speed is the whole game.
Sources: The Hacker News.