PT-2025-18114 · Unknown · Enterprise Protection

Published

2025-04-28

·

Updated

2025-10-06

·

CVE-2024-10635

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Enterprise Protection (affected versions not specified)
Description The issue is related to an improper input validation vulnerability in the attachment defense of Enterprise Protection. This vulnerability allows an unauthenticated remote attacker to bypass attachment scanning security policy by sending a malicious S/MIME attachment with an opaque signature. When opened by a recipient in a downstream email client, the malicious attachment could cause partial loss of integrity and confidentiality to their system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Check for Exceptional Conditions

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-10635

Affected Products

Enterprise Protection