As a result of an unquoted service path vulnerability present in the Kiwi CatTools Installation Wizard, a local attacker could gain escalated privileges by inserting an executable into the path of the affected service or uninstall entry.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-21873 As a result of an unquoted service path vulnerability present in the Kiwi CatTools Installation Wizard, a local attacker could gain escalated privileges by inserting an executable into the path of the affected service or uninstall entry.
Fixes

Solution

SolarWinds advises Kiwi CatTools customers to upgrade to the latest version (3.11.9) once it becomes generally available.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: SolarWinds

Published:

Updated: 2024-09-16T18:39:55.907Z

Reserved: 2021-06-22T00:00:00

Link: CVE-2021-35230

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-10-22T12:15:07.973

Modified: 2024-11-21T06:12:06.577

Link: CVE-2021-35230

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses