File-Extension Filtering Vulnerability in Proofpoint Enterprise Protection
CVE-2019-19680
8.8HIGH
Summary
A file-extension filtering vulnerability exists in Proofpoint Enterprise Protection (PPS / PoD) that allows malicious actors to exploit flaws in the filtering mechanisms for file extensions and MIME types. This vulnerability affects unpatched versions of PPS through 8.9.22 and PoD through 8.14.2, enabling attackers to send malformed multipart emails that can bypass virus detection and potentially compromise system integrity.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved