Impact
A deserialization weakness (CWE‑502) in Kiteworks Core allows crafted data to be unsafely deserialized, potentially leading to remote code execution on the appliance. The flaw resides in the processing of untrusted serialized payloads, giving an attacker the possibility to execute arbitrary code if the payload is successfully processed. No generic bypass is available and the vulnerability remains conditional on attacker influence over the data fed to the deserialization routine.
Affected Systems
The vulnerability affects Kiteworks Core installations before version 9.5.0. Service descriptions are limited to the Core product; no specific sub‑components list is provided.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity risk; however, the EPSS score is unavailable and the vulnerability is not listed in CISA KEV, suggesting a lower likelihood of immediate exploitation. The attack vector is likely remote, requiring the attacker to deliver crafted serialized data to the affected application. Since exploitation depends on an attacker controlling the input data, the vulnerability is not automatically exploitable on its own and would require prior compromise or a separate vector to influence the payload.
OpenCVE Enrichment