EIP-2026-117926
PRE-CVESolarWinds Kiwi Syslog Server 8.3.52 - 'Kiwi Syslog Server' Unquoted Service Path
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-117926. PoCs published by Carlos A Garcia R.
AI-analyzed exploit summary This exploit leverages an unquoted service path vulnerability in SolarWinds Kiwi Syslog Server 8.3.52, allowing an attacker to escalate privileges by placing a malicious executable in the root of the C: drive, which gets executed as Local System when the service restarts.
Description
SolarWinds Kiwi Syslog Server 8.3.52 - 'Kiwi Syslog Server' Unquoted Service Path
Exploits (1)
This exploit leverages an unquoted service path vulnerability in SolarWinds Kiwi Syslog Server 8.3.52, allowing an attacker to escalate privileges by placing a malicious executable in the root of the C: drive, which gets executed as Local System when the service restarts.