Kiteworks Patches 126 Critical and High Severity Vulnerabilities
Key Takeaways Kiteworks has released a significant security update addressing 126 vulnerabilities across its secure data transfer platform and related applications. The vulnerabilities range from...
Key Takeaways
- Kiteworks has released a significant security update addressing 126 vulnerabilities across its secure data transfer platform and related applications.
- The vulnerabilities range from critical account takeover flaws and high-severity code execution bugs to data modification and privilege escalation issues.
- Kiteworks Core, Kiteworks Secure Data Forms, and Kiteworks Email Protection Gateway are the primary products affected.
- Immediate patching to version 9.5.1 or later is strongly recommended for all affected deployments to mitigate potential risks.
Kiteworks Addresses 126 Critical and High-Severity Flaws in Major Security Update
Kiteworks has rolled out a comprehensive security patch designed to remediate 126 vulnerabilities impacting its secure data transfer platform and associated software. This extensive update tackles a broad spectrum of security weaknesses, including critical account takeover vulnerabilities, high-severity arbitrary code execution flaws, security bypasses, unauthorized data modification, privilege escalation, and denial-of-service conditions.
Table Of Content
The company has made public the details of these vulnerabilities through its security advisories repository, offering specific version information and remediation guidance for its product suite.
Affected Products and Critical Vulnerabilities
Organizations utilizing Kiteworks Core, Kiteworks Secure Data Forms, and Kiteworks Email Protection Gateway are urged to promptly review their deployed versions and apply the latest security updates. The most severe issues primarily affect Kiteworks Core and Kiteworks Email Protection Gateway versions preceding 9.5.1.
Among these are two critical account takeover vulnerabilities, identified as GHSA-xgh2-fgj6-w93r and GHSA-c9w5-4frw-7wqq. Successful exploitation of these flaws could grant an attacker full control over a user account. This unauthorized access might lead to the compromise of sensitive files, email workflows, data-sharing capabilities, or even administrative functions, depending on the privileges associated with the breached account.
Code Execution and Privilege Escalation Risks
Kiteworks Core versions prior to 9.5.1 were also susceptible to an arbitrary code execution vulnerability, tracked as GHSA-gmgg-7xhc-75f9. Such code execution flaws pose a significant threat, as they enable attackers to execute malicious commands directly on a target server. In an enterprise context, this could facilitate data exfiltration, establish persistent access, enable lateral movement within the network, or even deploy ransomware.
Another high-severity vulnerability in Kiteworks Core, GHSA-m39v-w8fv-gf3m, could lead to privilege escalation. This means an attacker with limited system access might be able to elevate their permissions beyond those initially granted by administrators.
Additionally, Kiteworks Core received a fix for GHSA-h97r-j99c-q8xc, a moderate-severity flaw that could expose internal network resources to unauthorized parties.
Issues in Email Protection Gateway and Secure Data Forms
The update also addresses several vulnerabilities within Kiteworks Email Protection Gateway versions released before 9.5.1. These include unauthorized file modification flaws, designated GHSA-5pgq-v8g2-rg2f and GHSA-3p9g-jh62-8f89, which could allow malicious alterations to files processed or protected by the gateway. A moderate-severity denial-of-service issue, GHSA-wwhf-5862-rjxq, was also patched, preventing potential disruptions to email security operations.
Kiteworks Secure Data Forms versions predating 9.5.0 were affected by GHSA-9×72-vqwh-v4hv, a high-severity vulnerability permitting unauthorized data modification. Furthermore, a separate high-severity security bypass issue, GHSA-vwvw-rp3m-rm37, was resolved in Secure Data Forms versions before 9.5.1.
Kiteworks has stated that it discloses vulnerability details for up to 12 months following the release of a corresponding fix. Existing customers can access product-specific remediation information via release notes accompanying each update.
What You Should Do
- Immediately upgrade all affected Kiteworks deployments to version 9.5.1 or later.
- Verify the security posture of any internet-facing Kiteworks services, including Core, Email Protection Gateway, and Secure Data Forms instances.
- Conduct a thorough review of account activity for any suspicious access or anomalies, particularly for administrative accounts.
- Ensure that all administrative accounts are secured with strong authentication controls, such as multi-factor authentication (MFA).
- Assess whether any internet-facing Kiteworks instances were accessible to the public internet prior to applying the patches.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.