CVE-2024-3459
EUVD-2024-3204614.05.2024, 15:41
KioWare for Windows (versions all through 8.34) allows to escape the environment by downloading PDF files, which then by default are opened in an external PDF viewer. By using built-in functions of that viewer it is possible to launch a web browser, search through local files and, subsequently, launch any program with user privileges.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| kioware | kioware | 𝑥 ≤ 8.34 |
| kioware | kioware | 𝑥 ≤ 8.34 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration