Generated remediation guidance and an executive summary. No account required.
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application server's WriteWindowMouse API. The vulnerability allows an anonymous remote attacker to execute arbitrary code with local administrator privileges. The vulnerability is caused by improper deserialization.
Cite this page
CVE-2020-10655. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2020-10655
Use CWE-502, Proofpoint vendor hub and Insider Threat Management Server product page to widen CVE-2020-10655 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-40842, CVE-2020-10658 and CVE-2020-10656 for nearby disclosures in the same product family. Additional editorial context is available in Weekly Security Roundup: Navigating the April 2026 Threat Landscape and Critical Framework Exploits.