VendorsProofPointinsider_threat_managementany version
Vulnerabilities

ProofPoint Insider Threat Management 6.3 for Windows any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2020-8884
rcdsvc in the Proofpoint Insider Threat Management Windows Agent (formerly ObserveIT Windows Agent) before 7.9 allows remote authenticated users to execute arbitrary code as SYSTEM because of improper deserialization over named pipes.
Published 2021-01-06 · Modified
9.0EPSS 0.041
CVE-2021-27900
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) is missing an authorization check on several pages in the Web Console. This enables a view-only user to change any configuration setting and delete any registered agents. All versions before 7.11.1 are affected.
Published 2021-04-06 · Modified
8.1EPSS 0.025
CVE-2021-22159
Insider Threat Management Windows Agent Local Privilege Escalation Vulnerability The Proofpoint Insider Threat Management (formerly ObserveIT) Agent for Windows before 7.4.3, 7.5.4, 7.6.5, 7.7.5, 7.8.4, 7.9.3, 7.10.2, and 7.11.0.25 as well as versions 7.3 and earlier is missing authentication for a critical function, which allows a local authenticated Windows user to run arbitrary commands with the privileges of the Windows SYSTEM user. Agents for MacOS, Linux, and ITM Cloud are not affected.
Published 2021-01-26 · Modified
7.8EPSS 0.003
CVE-2022-25294
Proofpoint Insider Threat Management Agent for Windows relies on an inherently dangerous function that could enable an unprivileged local Windows user to run arbitrary code with SYSTEM privileges. All versions prior to 7.12.1 are affected. Agents for MacOS and Linux and Cloud are unaffected. Proofpoint has released fixed software version 7.12.1. The fixed software versions are available through the customer support portal.
Published 2022-03-07 · Modified
7.8EPSS 0.003
CVE-2023-4801
ITM MacOS Agent Improper Certificate Validation
Published 2023-09-13 · Modified
7.5EPSS 0.003
CVE-2021-27899
The Proofpoint Insider Threat Management Agents (formerly ObserveIT Agent) for MacOS and Linux perform improper validation of the ITM Server's certificate, which enables a remote attacker to intercept and alter these communications using a man-in-the-middle attack. All versions before 7.11.1 are affected. Agents for Windows and Cloud are not affected.
Published 2021-04-06 · Modified
7.4EPSS 0.006
CVE-2021-22158
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) is vulnerable to XML external entity (XXE) injection in the Web Console. The vulnerability requires admin user privileges and knowledge of the XML file's encryption key to successfully exploit. All versions before 7.11 are affected.
Published 2021-04-06 · Modified
7.2EPSS 0.006
CVE-2023-4828
ITM Server Communications Hijack
Published 2023-09-13 · Modified
6.4EPSS 0.004
CVE-2021-22157
Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.11.1 allows stored XSS.
Published 2021-04-06 · Modified
6.1EPSS 0.019
CVE-2023-2818
ITM Windows Agent Insecure Filesystem Permissions
Published 2023-06-27 · Modified
5.5EPSS 0.002
CVE-2023-4802
ITM Server Cross-site Scripting in UpdateInstalledSoftware Endpoint
Published 2023-09-13 · Modified
4.8EPSS 0.004
CVE-2023-4803
ITM Server Cross-site Scripting in WriteWindowTitle Endpoint
Published 2023-09-13 · Modified
4.8EPSS 0.004