Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a vulnerability in the Kiteworks Email Protection Gateway that could allow an unauthorized sender to trick the system into accessing internal resources. This capability might expose sensitive information or alter the state of internal services by making requests on behalf of the gateway. The primary concern is to determine if your organization uses this technology and if it is exposed to external email.
- System could be tricked into accessing internal resources.
- Email gateways are often public-facing, increasing risk.
- Confirm use and exposure to understand potential impact.
Attack Path
How an attacker could exploit the issue
An attacker could send a specially crafted email to the Kiteworks Email Protection Gateway. The gateway would then make a server-side request to a URL within that email without sufficient restrictions on where it can connect. This could allow the attacker to access internal systems or cloud metadata, potentially revealing sensitive information or altering internal service states.
- Entry requires unauthenticated network access.
- Triggered by processing malicious email content.
- Risk of sensitive data exposure and service manipulation.
Live Threat
Current exploitation, exposure, and threat context
A remote, unauthenticated sender could craft a malicious email message to trigger the Kiteworks Email Protection Gateway to make requests to internal services or cloud instance metadata endpoints. This could potentially expose sensitive internal data or alter the state of internal services.
- Internal network information could be exposed.
- Gateway fetches URLs from email content.
- Internal service states may be affected.
Operational Fix
Recommended remediation, mitigation, and detection steps
The Kiteworks Email Protection Gateway's Server-Side Request Forgery vulnerability requires a coordinated response. Typically, the platform or infrastructure team responsible for the gateway's deployment should lead the remediation effort. The first practical step is to identify all instances of the gateway, confirm their exposure and business criticality, and then engage the appropriate application or security teams to plan and execute mitigation strategies, potentially involving vendor coordination.
- Platform or infrastructure teams own remediation.
- Verify gateway exposure and business criticality.
- Plan mitigation and coordinate with vendor.