CVE-2024-3676 - CVE House
Back to Database
Status published High CVE-2024-3676

The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains an...

Vulnerability Description

The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains an Improper Input Validation vulnerability that allows an unauthenticated remote attacker with a specially crafted HTTP request to create additional Encryption user accounts under the attacker's control.  These accounts are able to send spoofed email to any users within the domains configured by the Administrator.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-3676

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Enterprise Protection
Vulnerable Versions:
8.18.6, 8.20.0, 8.20.2, 8.20.4, 8.21.0

Timeline

Official Publish: May 14th, 2024
Last Modified: August 1st, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Weaknesses (CWE)