Proofpoint Enterprise Protection (PPS/PoD) before 8.16.4 contains a vulnerability that could allow an attacker to deliver an email message with a malicious attachment that bypasses scanning and file-blocking rules. The vulnerability exists because messages with certain crafted and malformed multipart structures are not properly handled.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14009
Reference (s):
- https://www.proofpoint.com/us/security/security-advisories
- https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2021-0006

