vendor:
Kiwi Syslog Server
by:
Carlos A Garcia R
N/A
CVSS
MEDIUM
Unquoted Service Path
428
CWE
Product Name: Kiwi Syslog Server
Affected Version From: 8.3.52
Affected Version To: 8.3.52
Patch Exists: NO
Related CWE:
CPE: a:solarwinds:kiwi_syslog_server:8.3.52
Platforms Tested: Windows XP Professional Service Pack 3
2019
SolarWinds Kiwi Syslog Server 8.3.52 – ‘Kiwi Syslog Server’ Unquoted Service Path
The SolarWinds Kiwi Syslog Server 8.3.52 software has an unquoted service path vulnerability. This allows an attacker to place an executable named 'Archivos.exe' in the root directory and have it executed as the Local System user when the service is restarted.
Mitigation:
Apply the vendor-supplied patch to fix the unquoted service path vulnerability. Additionally, ensure that all software on the system is up to date.