CVE-2024-10635
28.04.2025, 21:15
Enterprise Protection contains an improper input validation vulnerability in attachment defense that allows an unauthenticated remote attacker to bypass attachment scanning security policy by sending a malicious S/MIME attachment with an opaque signature. When opened by a recipient in a downstream email client, the malicious attachment could cause partial loss of integrity and confidentiality to their system.Enginsight
Vendor | Product | Version |
---|---|---|
proofpoint | enterprise_protection | 8.18.6 |
proofpoint | enterprise_protection | 8.20.6 |
proofpoint | enterprise_protection | 8.21.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration