CVE-2024-10635
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Apr 28, 2025
Updated: May 10, 2025
CWE ID 20
Summary
CVE-2024-10635 is a newly identified vulnerability affecting Enterprise Protection's attachment defense. The issue involves improper input validation, enabling unauthenticated remote attackers to bypass the attachment scanning security policy. They can do this by sending a maliciously crafted S/MIME attachment with an opaque signature. Once opened by a recipient in a downstream email client, these malicious attachments could result in partial loss of integrity and confidentiality to the affected system.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Proofpoint