Impact
Kiteworks Email Protection Gateway before version 9.5.0 contains an unsafe reflection flaw that allows an authenticated administrator with mail‑rule configuration rights to load and execute arbitrary code from an imported rule set. The code runs under the gateway’s service account, giving the attacker the ability to compromise the mail‑gateway process, exfiltrate data, or pivot to other systems. The weakness is identified as CWE‑470.
Affected Systems
The vulnerability affects Kiteworks Email Protection Gateway products with a version earlier than 9.5.0. Administrators who manage mail‑rule configurations on these servers are at risk. The product name is Kiteworks: Email Protection Gateway.
Risk and Exploitability
The CVSS score is 7.2, indicating a medium to high severity. EPSS is not available, and the issue is not listed in CISA’s KEV catalog. An attacker must be authenticated as an administrator with mail‑rule configuration privileges. Once privileged access is obtained, the attacker can supply a crafted rule configuration that injects code, leading to remote code execution on the gateway service account.
OpenCVE Enrichment