KioWare for Windows (versions all through 8.34) allows to escape the environment by downloading PDF files, which then by default are opened in an external PDF viewer. By using built-in functions of that viewer it is possible to launch a web browser, search through local files and, subsequently, launch any program with user privileges.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-32046 KioWare for Windows (versions all through 8.34) allows to escape the environment by downloading PDF files, which then by default are opened in an external PDF viewer. By using built-in functions of that viewer it is possible to launch a web browser, search through local files and, subsequently, launch any program with user privileges.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 12 Feb 2025 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Kioware
Kioware kioware
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:kioware:kioware:*:*:*:*:*:windows:*:*
Vendors & Products Kioware
Kioware kioware

cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2024-08-01T20:12:07.655Z

Reserved: 2024-04-08T10:30:34.586Z

Link: CVE-2024-3459

cve-icon Vulnrichment

Updated: 2024-08-01T20:12:07.655Z

cve-icon NVD

Status : Analyzed

Published: 2024-05-14T15:41:12.060

Modified: 2025-02-12T01:48:00.043

Link: CVE-2024-3459

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.