CVE-2020-14009: Proofpoint Enterprise Protection

Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Proofpoint Enterprise Protection (PPS/PoD) before 8.16.4 contains a vulnerability that could allow an attacker to deliver an email message with a malicious attachment that bypasses scanning and file-blocking rules. The vulnerability exists because messages with certain crafted and malformed multipart structures are not properly handled.

Affected products

  • Proofpoint Enterprise Protection: before 8.13.16 (fixed in 8.13.16); from 8.14.0, before 8.16.4 (fixed in 8.16.4)

Published 2021-05-07. Last modified 2026-06-17.