Lucene search

K

Kioware Security Vulnerabilities

cve
cve

CVE-2018-18435

KioWare Server version 4.9.6 and older installs by default to "C:\kioware_com" with weak folder permissions granting any user full permission "Everyone: (F)" to the contents of the directory and it's sub-folders. In addition, the program installs a service called "KWSService" which runs as "Localsy...

7.8CVSS

7.6AI Score

0.002EPSS

2019-03-21 04:00 PM
39
cve
cve

CVE-2022-44875

KioWare through 8.33 on Windows sets KioScriptingUrlACL.AclActions.AllowHigh for the about:blank origin, which allows attackers to obtain SYSTEM access via KioUtils.Execute in JavaScript code.

5.4CVSS

5.4AI Score

0.001EPSS

2023-03-06 05:15 AM
26
cve
cve

CVE-2023-34641

KioWare for Windows through v8.33 was discovered to contain an incomplete blacklist filter for blocked dialog boxes on Windows 10. This issue can allow attackers to open a file dialog box via the function window.print() which can then be used to open an unprivileged command prompt.

7.8CVSS

7.8AI Score

0.0004EPSS

2023-06-19 05:15 AM
11
cve
cve

CVE-2023-34642

KioWare for Windows through v8.33 was discovered to contain an incomplete blacklist filter for blocked dialog boxes on Windows 10. This issue can allow attackers to open a file dialog box via the function showDirectoryPicker() which can then be used to open an unprivileged command prompt.

7.8CVSS

7.8AI Score

0.0004EPSS

2023-06-19 05:15 AM
18