Impact
The vulnerability involves the deserialization of crafted serialized objects by the Kiteworks Email Protection Gateway without adequate validation. An attacker who is an authenticated administrator with queue‑management privileges can submit a malicious payload to the cluster management interface, potentially causing arbitrary code execution within the gateway service account. This weakness is classified as CWE‑502, which indicates unsafe deserialization leading to remote code execution, a severe impact on confidentiality, integrity, and availability of the protected email environment.
Affected Systems
Kiteworks Email Protection Gateway is affected. The vulnerability is limited to instances where an authenticated administrator holds the queue‑management privilege; no specific version range is disclosed, so all versions that do not yet implement proper validation may be vulnerable.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity. No EPSS score is available, but the requirement for administrative credentials suggests that exploitation is possible primarily in environments where privileged accounts are compromised or misconfigured. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to authenticate as an administrator with queue‑management rights, send a crafted serialized object to the cluster management endpoint, and achieve code execution in the context of the gateway service account. Given the high severity and the privileged context, the risk is considered significant for affected deployments.
OpenCVE Enrichment