Impact
A privilege escalation flaw exists in Kiteworks Core where a privileged routine fails to sanitise a filesystem path supplied by an unprivileged backend service account. An attacker who can already run code as that service account could influence the path, causing the privileged routine to execute arbitrary commands with root privileges. The vulnerability leads to full system compromise on the appliance and allows the attacker to read, modify, or delete any data, as well as affect service availability.
Affected Systems
Kiteworks Core appliances are affected, but specific version numbers are not listed in the advisory. The issue applies to installations that contain the vulnerable privileged routine.
Risk and Exploitability
The CVSS score is 7.8, indicating high severity. No EPSS data is available and the vulnerability is not listed in the CISA KEV catalog, suggesting it may not be widely exploited yet. The exploit requires local access to the backend service account, so an attacker must already have compromised that account before escalating privileges.
OpenCVE Enrichment