← Back

CVE-2024-3459

nvd nist
Published: May 14, 2024Modified: Jun 17, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

KioWare for Windows (versions all through 8.34) allows to escape the environment by downloading PDF files, which then by default are opened in an external PDF viewer. By using built-in functions of that viewer it is possible to launch a web browser, search through local files and, subsequently, launch any program with user privileges.

Affected (1)

Products: Kioware: Kioware
1 product
Kioware
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 8.34

References (6)

Source: cvd@cert.pl
Broken Link
Source: cvd@cert.pl
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Product

Timeline

No history available yet.