PT-2021-9163 · Proofpoint · Proofpoint Insider Threat Management Server

Published

2021-01-06

·

Updated

2021-01-08

·

CVE-2020-10656

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Proofpoint Insider Threat Management Server versions prior to 7.9.1
Description The issue allows an anonymous remote attacker to execute arbitrary code with local administrator privileges. This is caused by improper deserialization in the ITM application server's "WriteWindowMouseWithChunksV2" API endpoint.
Recommendations For versions prior to 7.9.1, update to version 7.9.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the "WriteWindowMouseWithChunksV2" API endpoint until a patch is applied.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10656

Affected Products

Proofpoint Insider Threat Management Server