7.8 HIGH
- CVSS version: 3.1
- Attack vector (AV): LOCAL
- Attack complexity (AC): LOW
- Privileges required (PR): LOW
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): HIGH
- Availability impact (A): HIGH
Kite 1.2020.1119.0 - 'KiteService' Unquoted Service Path
Kite 1.2020.1119.0 contains an unquoted service path vulnerability in the KiteService Windows service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Kite\KiteService.exe' to inject malicious executables and escalate privileges on the system.
References
-
ExploitDB-49205 exploit
-
Vendor Homepage product
-
VulnCheck Advisory: Kite 1.2020.1119.0 - 'KiteService' Unquoted Service Path third-party-advisory
Affected products
- =<1.2020.1119.0
Matching in nixpkgs
pkgs.kitex
High-performance and strong-extensibility Golang RPC framework
pkgs.kiterunner
Contextual content discovery tool
pkgs.buildkite-cli
Command line interface for Buildkite
pkgs.buildkite-agent
Build runner for buildkite.com
pkgs.kdePackages.kiten
Japanese Reference/Study Tool
pkgs.libsForQt5.krohnkite
Dynamic tiling extension for KWin
pkgs.kdePackages.krohnkite
Dynamic Tiling Extension for KWin 6
pkgs.libsForQt5.kitemviews
None
pkgs.kdePackages.kitemviews
KItemViews
pkgs.libsForQt5.kitemmodels
None
pkgs.buildkite-agent-metrics
Command-line tool (and Lambda) for collecting Buildkite agent metrics
pkgs.kdePackages.kitemmodels
KItemModels
pkgs.plasma5Packages.krohnkite
Dynamic tiling extension for KWin
pkgs.plasma5Packages.kitemviews
None
pkgs.plasma5Packages.kitemmodels
None
pkgs.buildkite-test-collector-rust
Rust adapter for Buildkite Test Analytics
pkgs.terraform-providers.buildkite
None
pkgs.haskellPackages.PenroseKiteDart
Library to explore Penrose's Kite and Dart Tilings
pkgs.python312Packages.wikitextparser
Simple parsing tool for MediaWiki's wikitext markup
pkgs.python313Packages.wikitextparser
Simple parsing tool for MediaWiki's wikitext markup
pkgs.terraform-providers.buildkite_buildkite
None
Package maintainers
-
@jsoo1 John Soo <jsoo1@asu.edu>
-
@mostlyobvious Paweł Pacana <pawel.pacana@gmail.com>
-
@zimbatm zimbatm <zimbatm@zimbatm.com>
-
@techknowlogick techknowlogick <techknowlogick@gitea.com>
-
@grahamc Graham Christensen <graham@grahamc.com>
-
@cole-h Cole Helbling <cole.e.helbling@outlook.com>
-
@groodt Greg Roodt <groodt@gmail.com>
-
@jfroche Jean-François Roche <jfroche@pyxel.be>
-
@SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com>
-
@mjm Matt Moriarity <matt@mattmoriarity.com>
-
@LunNova Luna Nova <nixpkgs-maintainer@lunnova.dev>
-
@ilya-fedin Ilya Fedin <fedin-ilja2010@ya.ru>
-
@ttuegel Thomas Tuegel <ttuegel@mailbox.org>
-
@K900 Ilya K. <me@0upti.me>
-
@NickCao Nick Cao <nickcao@nichi.co>
-
@Ben9986 Ben Carmichael <ben9986.unvmn@passinbox.com>
-
@dramforever Vivian Wang <dramforever@live.com>
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>
-
@nyanloutre Paul Trehiou <paul@nyanlout.re>
-
@seqizz Gurkan Gur <seqizz@gmail.com>
-
@Steinhagen Viorel-Cătălin Răpițeanu <rapiteanu.catalin@gmail.com>