vendor:
Kiwi CatTools
by:
Halil Dalabasmaz
5.5
CVSS
MEDIUM
Unquoted Service Path Privilege Escalation
426
CWE
Product Name: Kiwi CatTools
Affected Version From:
Affected Version To:
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested: Windows
2016
SolarWinds Kiwi CatTools Unquoted Service Path Privilege Escalation Vulnerability
The vulnerability allows an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system. It occurs due to the application being installed as a service with an unquoted service path.
Mitigation:
Update to the latest version of Kiwi CatTools or uninstall the software if it is no longer needed.