Impact
The flaw is a path traversal condition that lets an authenticated administrator write a file outside the intended directory. The application then executes that file, giving the attacker the privileges of the underlying service account and enabling remote code execution.
Affected Systems
The vulnerability affects the Kiteworks Email Protection Gateway. No specific version or build information is provided, so all deployed instances of this gateway could be susceptible.
Risk and Exploitability
The CVSS score of 7.2 indicates a high impact with a required authenticated administrative attack vector. The EPSS score is unavailable and the CVE is not listed in the CISA KEV catalog. Because an attacker must be a legitimate administrator, the risk is mitigated to environments that tightly control administrative access, yet the potential to execute arbitrary code remains serious if these accounts are compromised.
OpenCVE Enrichment