CVE-2024-3459
14.05.2024, 15:41
KioWare for Windows (versions allthrough 8.34)allows to escape the environment by downloading PDF files, which then by default are opened in an external PDF viewer. By using built-in functions of that viewer it is possible to launch a web browser, search through local files and, subsequently, launch any program with user privileges.Enginsight
Vendor | Product | Version |
---|---|---|
kioware | kioware | 𝑥 ≤ 8.34 |
kioware | kioware | 𝑥 ≤ 8.34 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration