Mimecast · Mimecast Email Security · CVE-2020-36519
**Name of the Vulnerable Software and Affected Versions**
Mimecast Email Security versions prior to 2020-01-10
**Description**
The issue allows any admin to spoof any domain and pass DMARC alignment via SPF. This occurs through misuse of the address rewrite feature, but the domain being spoofed must be a customer in the Mimecast grid from which the spoofing occurs.
**Recommendations**
For versions prior to 2020-01-10, update to a version released after 2020-01-10 to resolve the issue. As a temporary workaround, consider restricting the use of the address rewrite feature to minimize the risk of exploitation.