cert.plThird-party advisory
https://cert.pl/en/posts/2024/04/CVE-2024-3459 CVE-2024-3459
HIGH
Record summary
CVE-2024-3459 has a selected CVSS score of 8.4 (high).
Description
KioWare for Windows (versions all through 8.34) allows to escape the environment by downloading PDF files, which then by default are opened in an external PDF viewer. By using built-in functions of that viewer it is possible to launch a web browser, search through local files and, subsequently, launch any program with user privileges.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 12, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
KiowareBrowse Kioware / KiowareDefault status: unaffected, unknown | CVE List | Through 8.34 | affected |
References
4cert.plThird-party advisory
https://cert.pl/posts/2024/04/CVE-2024-3459 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-3459 kioware.comproduct
https://www.kioware.com/