CVE-2020-10658

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
06/01/2021
Last modified:
08/01/2021

Description

The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application server's WriteImage API. The vulnerability allows an anonymous remote attacker to execute arbitrary code with local administrator privileges. The vulnerability is caused by improper deserialization.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:proofpoint:insider_threat_management_server:*:*:*:*:*:*:*:* 7.9.1 (excluding)