CVE-2024-10635 – Enterprise Protection S/MIME Attachment Defense Improper Input Validation

The following table lists the changes that have been made to the
CVE-2024-10635 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Apr. 28, 2025

    Action Type Old Value New Value
    Added Description Enterprise Protection contains an improper input validation vulnerability in attachment defense that allows an unauthenticated remote attacker to bypass attachment scanning security policy by sending a malicious S/MIME attachment with an opaque signature. When opened by a recipient in a downstream email client, the malicious attachment could cause partial loss of integrity and confidentiality to their system.
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
    Added CWE CWE-20
    Added Reference https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2025-0002
Share the Post:

Related Posts