Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gww7-xg42-6356

Опубликовано: 14 мая 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.4

Описание

KioWare for Windows (versions all through 8.34) allows to escape the environment by downloading PDF files, which then by default are opened in an external PDF viewer. By using built-in functions of that viewer it is possible to launch a web browser, search through local files and, subsequently, launch any program with user privileges.

KioWare for Windows (versions all through 8.34) allows to escape the environment by downloading PDF files, which then by default are opened in an external PDF viewer. By using built-in functions of that viewer it is possible to launch a web browser, search through local files and, subsequently, launch any program with user privileges.

EPSS

Процентиль: 25%
0.00084
Низкий

8.4 High

CVSS3

Дефекты

CWE-424

Связанные уязвимости

CVSS3: 8.4
nvd
больше 1 года назад

KioWare for Windows (versions all through 8.34) allows to escape the environment by downloading PDF files, which then by default are opened in an external PDF viewer. By using built-in functions of that viewer it is possible to launch a web browser, search through local files and, subsequently, launch any program with user privileges.

EPSS

Процентиль: 25%
0.00084
Низкий

8.4 High

CVSS3

Дефекты

CWE-424