Impact
In environments where the remote-support feature is licensed and enabled, the flaw allows an authenticated System Administrator who also holds the encryption key for transmitted data to hijack the defecting system’s outbound support channel to any destination chosen by the attacker. This can result in the execution of operating‑system commands on the target node and the retrieval of command output, effectively enabling remote code execution with the privileges of a local service account. The weakness is a combination of improper remote access control (CWE‑807) and misuse of privileged credentials (CWE‑940).
Affected Systems
The vulnerable product is Kiteworks Core. No specific version information is provided, but the issue applies to all deployments that have the remote-support capability licensed and enabled.
Risk and Exploitability
The CVSS score is 7.2, indicating a high level of severity. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog. Because the exploit requires authenticated access to a System Administrator account and possession of the support key, the attack vector is likely limited to insider or compromised administrator credentials. Given the high severity and the potential for full system compromise, organizations should treat this as a critical risk.
OpenCVE Enrichment