vendor:
Kite
by:
Ghaleb Al-otaibi
7.2
CVSS
HIGH
Unquoted Service Path
73
CWE
Product Name: Kite
Affected Version From: Version 4.2.0.1 U1
Affected Version To: Version 4.2.0.1 U1
Patch Exists: NO
Related CWE:
CPE: a:kite:kite:1.2021.610.0
Platforms Tested: Microsoft Windows 10 Pro - 10.0.19044 N/A Build 19044
2020
Kite 1.2021.610.0 – Unquoted Service Path
KiteService is a Windows service installed with Kite 1.2021.610.0. The service is configured to run with the LocalSystem account and has an unquoted service path. This can be exploited by a local attacker to gain elevated privileges.
Mitigation:
Ensure that all services have a fully qualified path with quotes around it.