Skip to content
Threat Feed
high advisory

Arbitrary Code Execution Vulnerability in Kiteworks Email Protection Gateway

An unauthenticated remote code execution vulnerability in Kiteworks Email Protection Gateway (EPG) allows attackers to gain root-level access via input-handling flaws in public endpoints.

A vulnerability has been identified in the Kiteworks Email Protection Gateway (EPG) that allows an unauthenticated remote attacker to achieve arbitrary code execution. The EPG platform, used for email encryption, decryption, and policy enforcement, contains input-handling flaws within its publicly accessible web endpoints. By exploiting these flaws, an attacker can execute arbitrary commands with root privileges on the underlying appliance. This represents a significant security risk for organizations using Kiteworks as a perimeter email security solution, as the appliance typically handles sensitive inbound and outbound communications. Successful exploitation leads to a complete system compromise, enabling attackers to intercept, read, or modify enterprise emails or pivot further into the internal network.

Impact

Successful exploitation of this vulnerability results in full administrative control over the targeted Email Protection Gateway. As the appliance is positioned at the network edge to manage encrypted email traffic, unauthorized root access allows for the total compromise of email data, potential credential theft, and sustained persistence within the organization's communication infrastructure. The number of potentially affected victims includes any enterprise relying on Kiteworks EPG for email security.

Recommendation

Prioritize monitoring of all public-facing Kiteworks EPG instances for anomalous requests originating from untrusted external IPs. Since no specific patch version or CVE identifier was provided in the initial security advisory, contact Kiteworks support immediately to confirm if your specific deployment version is affected and request the relevant security update or mitigation configuration.


Immediate actions

Inventory all internet-facing Kiteworks EPG appliances

IT Operations 24h

Restrict access to Kiteworks EPG management interfaces to authorized IP ranges

SOC 24h

Enrichment needed

  • Vulnerable version range (CTI) Current report does not specify which versions are exploitable

Mitigations

Contact Kiteworks support for current patches

immediate IT Operations

Email Protection Gateway