CVE-2024-10635

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Apr 28, 2025
Updated: May 10, 2025
CWE ID 20

Summary

CVE-2024-10635 is a newly identified vulnerability affecting Enterprise Protection's attachment defense. The issue involves improper input validation, enabling unauthenticated remote attackers to bypass the attachment scanning security policy. They can do this by sending a maliciously crafted S/MIME attachment with an opaque signature. Once opened by a recipient in a downstream email client, these malicious attachments could result in partial loss of integrity and confidentiality to the affected system.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share