Impact
Kiteworks Email Protection Gateway has a flaw in case‑sensitive validation that allows authenticated administrators to submit configuration data in an unrecognized form, resulting in arbitrary files being written to the gateway and executed. This flaw permits execution of code with the privileges of the gateway service account, effectively granting an attacker full control over the service and potentially the underlying host. The vulnerability is a form of input validation failure (CWE‑178) that leads to code execution (CWE‑94).
Affected Systems
The affected product is Kiteworks Email Protection Gateway. No specific version information is provided in the advisory, so all current installations of the product are potentially vulnerable until a vendor‑supplied fix is applied. Only administrators with authentication to the gateway can exploit the flaw.
Risk and Exploitability
The CVSS score of 7.2 indicates a high impact risk. Because the EPSS score is not available, the exploitation probability cannot be quantified, but the lack of a KEV listing suggests the vulnerability is not widely exploited yet. The attack requires valid administrator credentials and the ability to send configuration payloads to the gateway. Once exploited, the attacker can write and execute any file, leading to complete compromise of the gateway service account.」
OpenCVE Enrichment