216.73.217.22

CVE-2024-3459

· Published 14/05/2024 15:41 · Modified 14/05/2024 16:11

Labels: CVE-2024-3459 2024-05-14CVE-2024-3459CWE-424[email protected]

Essential information

Published
14/05/2024 15:41
Modified
14/05/2024 16:11
Author
Creator
CVSS
8.4 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

KioWare for Windows (versions all through 8.34) allows to escape the environment by downloading PDF files, which then by default are opened in an external PDF viewer. By using built-in functions of that viewer it is possible to launch a web browser, search through local files and, subsequently, launch any program with user privileges.

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

References