Описание
KioWare for Windows (versions all through 8.34) allows to escape the environment by downloading PDF files, which then by default are opened in an external PDF viewer. By using built-in functions of that viewer it is possible to launch a web browser, search through local files and, subsequently, launch any program with user privileges.
Ссылки
- Broken Link
- Broken Link
- Product
- Broken Link
- Broken Link
- Product
Уязвимые конфигурации
Конфигурация 1Версия до 8.34 (включая)
cpe:2.3:a:kioware:kioware:*:*:*:*:*:windows:*:*
EPSS
Процентиль: 25%
0.00084
Низкий
8.4 High
CVSS3
7.8 High
CVSS3
Дефекты
CWE-424
NVD-CWE-Other
Связанные уязвимости
CVSS3: 8.4
github
больше 1 года назад
KioWare for Windows (versions all through 8.34) allows to escape the environment by downloading PDF files, which then by default are opened in an external PDF viewer. By using built-in functions of that viewer it is possible to launch a web browser, search through local files and, subsequently, launch any program with user privileges.
EPSS
Процентиль: 25%
0.00084
Низкий
8.4 High
CVSS3
7.8 High
CVSS3
Дефекты
CWE-424
NVD-CWE-Other