The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains an Improper Input Validation vulnerability that allows an unauthenticated remote attacker with a specially crafted HTTP request to create additional Encryption user accounts under the attacker's control.  These accounts are able to send spoofed email to any users within the domains configured by the Administrator.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Proofpoint

Published: 2024-05-14T19:07:19.420Z

Updated: 2024-08-01T20:19:59.948Z

Reserved: 2024-04-11T20:00:59.260Z

Link: CVE-2024-3676

cve-icon Vulnrichment

Updated: 2024-08-01T20:19:59.948Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-14T19:15:12.970

Modified: 2024-05-14T19:17:55.627

Link: CVE-2024-3676

cve-icon Redhat

No data.