Impact
The vulnerability arises from a CWE-502 deserialization of untrusted data in the Kiteworks Email Protection Gateway. When database replication is enabled, a trusted peer can submit a crafted serialized object that the service processes without proper validation. This flaw can provide the attacker with full code execution privileges under the gateway service account, allowing manipulation, exfiltration, or further compromise of connected systems.
Affected Systems
It affects all deployments of the Kiteworks Email Protection Gateway that have database replication enabled. No specific version is disclosed, implying that any instance configured for replication is potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.6 indicates moderate severity, reflecting that exploitation requires a trusted cluster relationship or administrative access. Replication is disabled by default, reducing the attack surface, yet an attacker who compromises a trusted peer or gains administrator rights can achieve complete control. The EPSS score is not available and the flaw is not listed in the CISA KEV catalog, but the possibility of remote code execution warrants rapid mitigation.
OpenCVE Enrichment