Impact
A back‑end service running under an unprivileged account on a Kiteworks appliance can be coerced by an attacker who has already executed code locally into elevating privileges to root and executing any arbitrary command. The flaw is a classic privilege management weakness compounded by an operating system command injection vulnerability, allowing the attacker to gain full control over the system. This gives an attacker full confidentiality, integrity, and availability compromise of the compromised appliance.
Affected Systems
Kiteworks Core – the professional file‑sharing and collaboration appliance. No specific version information was provided in the available data, so all installations of the Core component are potentially affected until a vendor patch is issued.
Risk and Exploitability
The CVSS base score of 7.8 indicates a high severity vulnerability. The EPSS score is not available, so the likelihood of exploitation cannot be quantified, yet the vulnerability is not listed in the CISA KEV catalog. The attack requires local access to the backend service account that is already running code; once such local code execution is achieved, the escalation can be completed with no further external interaction.
OpenCVE Enrichment