KioWare for Windows (versions all through 8.34) allows to escape the environment by downloading PDF files, which then by default are opened in an external PDF viewer. By using built-in functions of that viewer it is possible to launch a web browser, search through local files and, subsequently, launch any program with user privileges.
References
Configurations
No configuration.
History
No history.
Information
Published : 2024-05-14 15:41
Updated : 2024-05-14 16:11
NVD link : CVE-2024-3459
Mitre link : CVE-2024-3459
CVE.ORG link : CVE-2024-3459
JSON object : View
Products Affected
No product.
CWE
CWE-424
Improper Protection of Alternate Path