vendor:
Kiwi Syslog Server
by:
Halil Dalabasmaz
6,1
CVSS
MEDIUM
Privilege Escalation
426
CWE
Product Name: Kiwi Syslog Server
Affected Version From: Kiwi Syslog Server 9.4.0
Affected Version To: Kiwi Syslog Server 9.4.2
Patch Exists: Yes
Related CWE: CVE-2016-7206
CPE: a:solarwinds:kiwi_syslog_server:9.4.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2016
SolarWinds Kiwi Syslog Server Unquoted Service Path Privilege Escalation Vulnerability
The SolarWinds Kiwi Syslog Server is vulnerable to privilege escalation due to an unquoted service path. An authorized but non-privileged local user can exploit this vulnerability to execute arbitrary code with elevated privileges on the system.
Mitigation:
The vendor has released a patch to address this vulnerability.