PT-2021-9164 · Proofpoint · Proofpoint Insider Threat Management Server

Published

2021-01-06

·

Updated

2021-01-08

·

CVE-2020-10657

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Proofpoint Insider Threat Management Server versions prior to 7.9.1
Description The issue is caused by improper deserialization in the ITM web console's ImportAlertRules feature, allowing a remote attacker with admin or config-admin privileges to execute arbitrary code with local administrator privileges.
Recommendations For versions prior to 7.9.1, update to version 7.9.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the ImportAlertRules feature in the ITM web console to minimize the risk of exploitation.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10657

Affected Products

Proofpoint Insider Threat Management Server