Impact
A local privilege escalation issue was discovered in Kiteworks Core versions prior to 9.5.0. An attacker who can spawn a shell under a low‑privileged service account could exploit the flaw to execute code with root privileges on the appliance. This elevation of privilege can lead to full system compromise, including unauthorized data access, modification, or disruption. The vulnerability is associated with CWE‑250 (Execution as Different User) and CWE‑59 (Dereferencing a Null Pointer) and allows an attacker to gain control of the entire environment.
Affected Systems
The affected product is Kiteworks Core for all platforms. Versions older than 9.5.0 are impacted; upgrades to 9.5.0 or later contain the fix.
Risk and Exploitability
The CVSS score is 7.8, indicating high severity, but the EPSS score is not available so the exact current exploitation likelihood cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Attackers require local access and a pre‑existing shell under a low‑privileged account, making it a local attack. If successfully exploited, the attacker can execute arbitrary commands as root, effectively controlling the entire appliance.
OpenCVE Enrichment