Impact
Kiteworks Email Protection Gateway before version 9.5.0 contains a path traversal flaw in an administrative import function that allows an authenticated administrator to write files to arbitrary locations on the server. The vulnerability could enable an attacker to place and execute arbitrary code on the underlying system, leading to full compromise of the affected host.
Affected Systems
The flaw affects installations of Kiteworks Email Protection Gateway whose version is older than 9.5.0. No other vendors or product variants are listed as impacted.
Risk and Exploitability
The CVSS score of 7.2 indicates high severity. No EPSS score is available, so the exact likelihood of exploitation is unknown, but the vulnerability is not yet listed in CISA’s KEV catalog. Exploitation requires authenticated administrative access; once logged in, the attacker can use the import function to write arbitrary files, potentially dropping web shells or modifying critical configuration files. The attack vector is limited to privileged users, reducing exposure to external attackers who cannot acquire administrator credentials.
OpenCVE Enrichment