CyberRota Analysis
AI-GeneratedKiteworks Email Protection Gateway versions prior to 9.5.0 are susceptible to Unsafe Reflection, allowing authenticated administrators with mail-rule configuration privileges to load and execute unauthorized code within the mail-processing pipeline. This vulnerability could lead to the execution of malicious code in the context of the mail-gateway service account, posing a significant risk to the integrity and security of email communications. Organizations using this gateway should prioritize patching to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Unsafe Reflection and does not sufficiently restrict the code that the mail-processing pipeline could load from an imported rule configuration. An authenticated administrator with mail-rule configuration privileges could cause the gateway to load and execute code beyond the approved set of mail-processing components, potentially in the context of the mail-gateway service account.