Horizon Alert
Summary of the vulnerability and why it matters
A critical vulnerability has been identified in Kiteworks Core that allows an unauthenticated attacker to reset user passwords, including administrative accounts, by exploiting an improper parameter validation in the password reset workflow. This could potentially lead to unauthorized access and control of sensitive systems.
- Attackers can reset passwords without email verification.
- Sensitive accounts could be compromised by external attackers.
- Confirm relevance and exposure to prevent unauthorized access.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker who knows a user's email address can reset that user's password without needing access to the reset email. This allows the attacker to log in as the user, potentially gaining administrative access.
- Unauthenticated network access required.
- Password reset parameter not validated.
- Unauthorized account access and control.
Live Threat
Current exploitation, exposure, and threat context
When supported by the advisory, an unauthenticated attacker who knows a user's email address could potentially reset that account's password and authenticate as that user, even if the account has administrative privileges.
- User accounts and their privileges.
- Password reset workflow allows unauthorized access.
- Compromised accounts could lead to unauthorized actions.
Operational Fix
Recommended remediation, mitigation, and detection steps
Determining ownership requires identifying where Kiteworks Core is deployed and confirming its business criticality, which then helps pinpoint the accountable team, likely a combination of application owners, infrastructure, or platform teams. The immediate priority is to confirm the presence and exposure of Kiteworks Core instances, assess their reachability and impact, and then proceed with a risk-based remediation plan, potentially involving vendor coordination or temporary mitigations if direct remediation is not immediately feasible.
- Own the issue: Application or infrastructure owners.
- Verify first: Kiteworks Core deployment and exposure.
- Action: Plan and coordinate remediation.