Horizon Alert
Summary of the vulnerability and why it matters
This advisory addresses an improper authentication vulnerability within an administrative service of the Kiteworks Email Protection Gateway. The issue allows an unauthenticated attacker with a valid administrator account to bypass password checks, potentially enabling them to create, modify, or delete internal users and managed domains, and alter security configurations. In some cases, this could lead to the removal of user accounts or administrative lockout from the gateway.
- Authentication bypass in email gateway admin.
- High impact to data and access controls.
- Confirm relevance and assess potential exposure.
Attack Path
How an attacker could exploit the issue
An attacker could bypass authentication for an administrative service within Kiteworks Email Protection Gateway. By referencing a valid administrator account, an unauthenticated attacker could gain the ability to manage internal users and domains, including altering security settings or deleting domains and their associated user accounts. This could lead to significant disruption and unauthorized control over the gateway's configuration and user data.
- No authentication required for access.
- Bypass password check for administrative actions.
- Unauthorized user/domain management and configuration changes.
Live Threat
Current exploitation, exposure, and threat context
An administrative service in the Kiteworks Email Protection Gateway could allow an unauthenticated attacker to bypass password checks. When supported by the advisory, this could enable an attacker to create, modify, or delete internal users and managed domains, and alter security configurations.
- Administrative service settings at risk.
- Password check bypass could occur.
- Administrator lockout is a consequence.
Operational Fix
Recommended remediation, mitigation, and detection steps
The Kiteworks Email Protection Gateway's administrative service is likely managed by the platform or infrastructure team, with oversight from the security operations team due to its critical function. The first practical step is to identify all instances of this gateway within the environment, confirm their network exposure and business criticality, and then assign ownership to the accountable team for remediation planning.
- Platform or infrastructure teams own the issue.
- Verify gateway reachability and business criticality.
- Plan remediation based on identified risk.