File-Extension Filtering Vulnerability in Proofpoint Enterprise Protection
CVE-2019-19680

8.8HIGH

Key Information:

Vendor
Proofpoint
Vendor
CVE Published:
13 January 2020

Summary

A file-extension filtering vulnerability exists in Proofpoint Enterprise Protection (PPS / PoD) that allows malicious actors to exploit flaws in the filtering mechanisms for file extensions and MIME types. This vulnerability affects unpatched versions of PPS through 8.9.22 and PoD through 8.14.2, enabling attackers to send malformed multipart emails that can bypass virus detection and potentially compromise system integrity.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2019-19680 : File-Extension Filtering Vulnerability in Proofpoint Enterprise Protection | SecurityVulnerability.io