Proofpoint Enterprise Protection Endpoint Vulnerable to Improper Input Validation Attacks
CVE-2024-3676
7.5HIGH
What is CVE-2024-3676?
The Proofpoint Encryption component of Proofpoint Enterprise Protection is vulnerable due to improper input validation. This flaw enables unauthenticated remote attackers to exploit the system via specially crafted HTTP requests, potentially allowing the creation of additional encryption user accounts that are under their control. These malicious accounts can send spoofed emails to users within any configured domains, posing significant risks to organizations and compromising the integrity of email communications.
Affected Version(s)
Enterprise Protection 8.18.6
Enterprise Protection 8.18.6
Enterprise Protection 8.20.0