CVE-2024-3459

Published May 14, 2024

Last updated 12 days ago

Overview

Description
KioWare for Windows (versions all through 8.34) allows to escape the environment by downloading PDF files, which then by default are opened in an external PDF viewer. By using built-in functions of that viewer it is possible to launch a web browser, search through local files and, subsequently, launch any program with user privileges.
Source
cvd@cert.pl
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

cvd@cert.pl
CWE-424
nvd@nist.gov
NVD-CWE-Other

Social media

Hype score
Not currently trending

Configurations