Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2019-20634

Description

An issue was discovered in Proofpoint Email Protection through 2019-09-08. By collecting scores from Proofpoint email headers, it is possible to build a copy-cat Machine Learning Classification model and extract insights from this model. The insights gathered allow an attacker to craft emails that receive preferable scores, with a goal of delivering malicious emails.

POC

Reference

No PoCs from references.

Github

- https://github.com/gmh5225/Awesome-ML-Security_

- https://github.com/moohax/Proof-Pudding

- https://github.com/trailofbits/awesome-ml-security

- https://github.com/vadhri/ai-notebook