CVE report
CVE-2019-9670criticalKEV
Synacor Zimbra Collaboration <8.7.11p10 - XML External Entity Injection
Events 90d
31
Distinct IPs
10
Severity
critical
CISA KEV
Actively exploited
Detection signature
An event counts toward CVE-2019-9670 when its URL path contains any of these (case-insensitive). This is what our matching is based on.
- · /Autodiscover/Autodiscover.xml
Pre-disclosure activity
all early actors →Analysing probe history around the publication date…
Recent probe volume (last 7 days)
peak: 7 events/dayeventsdistinct IPs
Downloads & integrations
Top sources probing for CVE-2019-9670
- 179.43.186.2417 eventsSwitzerland· Private Layer INC
- 74.249.104.1936 eventsUnited States· Microsoft Corporation
- 20.17.96.2444 eventsMalaysia· Microsoft Corporation
- 100.48.18.2244 eventsUnited States
- 179.43.163.263 eventsSwitzerland· Private Layer INC
- 79.124.40.1743 eventsBulgaria· Tamatiya EOOD
- 20.51.193.861 eventsUnited States· Microsoft Corporation
- 20.251.66.631 eventsNorway· Microsoft Corporation
- 101.36.125.581 eventsHong Kong· UCLOUD INFORMATION TECHNOLOGY HK LIMITED
- 185.177.72.231 eventsFrance· Bucklog SARL
Top networks the attempts come from
Fingerprints of the clients exploiting this
The HTTP (JA4H) and TLS (JA4) fingerprints seen on these attempts. Click one to see the whole population that carries it.
ja4h: ge11nn0500_2223cffcb26cja4h: po11nn0700_e1eadaf42879ja4h: ge11nn14en_068ebe3632ecja4h: po11nn0500_b4ba55311b46ja4h: ge11nn0400_91d9e55fb80aja4h: ge11nn0400_9c3956fad5daja4: t13i4310h1_c7886603b240_7379471da272ja4: t13i130900_f57a46bbacb6_e7c285222651ja4: t13i190800_9dc949149365_97f8aa674fd9ja4: t13i140900_cbb2034c60b8_e7c285222651ja4: t13i100800_61a7ad8aa9b6_d268365384ff
Sample request paths observed
- /Autodiscover/Autodiscover.xml
- /autodiscover/autodiscover.xml/
- /autodiscover/autodiscover.xml