First published: Wed Jan 06 2021(Updated: )
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application server's WriteWindowMouseWithChunksV2 API. The vulnerability allows an anonymous remote attacker to execute arbitrary code with local administrator privileges. The vulnerability is caused by improper deserialization.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Proofpoint | <7.9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10656 is a vulnerability in the Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before version 7.9.1.
The severity of CVE-2020-10656 is critical, with a severity value of 9.8.
CVE-2020-10656 allows an anonymous remote attacker to execute arbitrary code with local administrator privileges on the Proofpoint Insider Threat Management Server before version 7.9.1.
To fix CVE-2020-10656, you should upgrade the Proofpoint Insider Threat Management Server to version 7.9.1 or later.
More information about CVE-2020-10656 can be found on the Proofpoint blog and the Proofpoint security advisories page.