Impact
Code executing inside the Kiteworks Core sandbox can escape confinement and act with the privileges of the service account that runs the application. This flaw allows a malicious actor already able to run code in the sandbox to read or modify application data and configuration, or to disrupt the service. The vulnerability is a sandbox escape (CWE-653) coupled with privilege escalation (CWE-668). The CVSS score of 8.8 indicates high severity, but the EPSS score is not available and the vulnerability is not listed in CISA KEV.
Affected Systems
Kiteworks Core is affected, but no specific version information is listed in the advisory.
Risk and Exploitability
With a high CVSS score and the lack of an exploitation probability metric, the risk remains significant. Attackers would first need to supply malicious content that triggers code execution within the sandbox; from there they could escape to the service account. The likelihood of exploitation is uncertain due to missing EPSS data, but the potential impact includes unauthorized data access, configuration tampering, and service disruption.
OpenCVE Enrichment