Proofpoint Enterprise Protection
cpe:2.3:a:proofpoint:enterprise_protection:*:*:*:*:*:*:*
- < 8.18.6 patch 5110
- < 8.20.6 patch 5134
- < 8.21.0 patch 5112
- < 8.22.0
A vulnerability exists in Proofpoint Enterprise Protection's attachment scanning feature, allowing an unauthenticated remote attacker to bypass attachment scanning policies. This is achieved by sending a malicious S/MIME attachment with an opaque signature. When the attachment is opened by a recipient using a downstream email client, it could lead to a partial loss of integrity and confidentiality on their system.
Exploitation of this vulnerability could result in a bypass of attachment scanning policies, allowing malicious S/MIME attachments to be delivered to users' inboxes. When these attachments are opened, they could cause a partial loss of integrity and confidentiality on the user's system.
Proofpoint has released patches for this vulnerability. On-premises customers running a supported version that automatically deploys releases do not need to take any action, as the fix has already been applied. Those in environments that manually apply releases should install the latest patch. Customers running an end-of-life version should upgrade to a supported release.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.