As a result of an unquoted service path vulnerability present in the Kiwi CatTools Installation Wizard, a local attacker could gain escalated privileges by inserting an executable into the path of the affected service or uninstall entry.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-21873 | As a result of an unquoted service path vulnerability present in the Kiwi CatTools Installation Wizard, a local attacker could gain escalated privileges by inserting an executable into the path of the affected service or uninstall entry. |
Fixes
Solution
SolarWinds advises Kiwi CatTools customers to upgrade to the latest version (3.11.9) once it becomes generally available.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: SolarWinds
Published:
Updated: 2024-09-16T18:39:55.907Z
Reserved: 2021-06-22T00:00:00
Link: CVE-2021-35230
No data.
Status : Modified
Published: 2021-10-22T12:15:07.973
Modified: 2024-11-21T06:12:06.577
Link: CVE-2021-35230
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD