8.5 HIGH
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Local (L)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): High (H)
- Vulnerable System Impact Integrity (VI): High (H)
- Vulnerable System Impact Availability (VA): High (H)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Local (L)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): High (H)
- Modified Vulnerable System Impact Integrity (MVI): High (H)
- Modified Vulnerable System Impact Availability (MVA): High (H)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse dismissed (not in Nixpkgs)
Kite 4.2.0.1 U1 Unquoted Service Path Privilege Escalation
Kite 4.2.0.1 U1 contains an unquoted service path vulnerability in the KiteService Windows service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious executable in the Program Files directory to be executed with LocalSystem privileges when the service starts.
References
-
ExploitDB-50975 exploit
-
Official Product Homepage product
-
VulnCheck Advisory: Kite 4.2.0.1 U1 Unquoted Service Path Privilege Escalation third-party-advisory
Affected products
- ==4.2.0.1 U1
Matching in nixpkgs
pkgs.kitex
High-performance and strong-extensibility Golang RPC framework
pkgs.kiterunner
Contextual content discovery tool
pkgs.buildkite-cli
Command line interface for Buildkite
pkgs.buildkite-agent
Build runner for buildkite.com
pkgs.kdePackages.kiten
Japanese Reference/Study Tool
pkgs.kdePackages.krohnkite
Dynamic Tiling Extension for KWin 6
pkgs.libsForQt5.kitemviews
None
pkgs.kdePackages.kitemviews
KItemViews
pkgs.libsForQt5.kitemmodels
None
pkgs.buildkite-agent-metrics
Command-line tool (and Lambda) for collecting Buildkite agent metrics
pkgs.kdePackages.kitemmodels
KItemModels
pkgs.plasma5Packages.kitemviews
None
pkgs.plasma5Packages.kitemmodels
None
pkgs.buildkite-test-collector-rust
Rust adapter for Buildkite Test Analytics
pkgs.terraform-providers.buildkite
None
pkgs.haskellPackages.PenroseKiteDart
Library to explore Penrose's Kite and Dart Tilings
pkgs.python312Packages.wikitextparser
None
pkgs.python313Packages.wikitextparser
Simple parsing tool for MediaWiki's wikitext markup
pkgs.python314Packages.wikitextparser
Simple parsing tool for MediaWiki's wikitext markup
pkgs.python313Packages.wikitextprocessor
Parser and expander for Wikipedia, Wiktionary etc. dump files, with Lua execution support
-
nixos-unstable 0.4.96-unstable-2026-03-06
- nixpkgs-unstable 0.4.96-unstable-2026-03-06
- nixos-unstable-small 0.4.96-unstable-2026-03-06
pkgs.python314Packages.wikitextprocessor
Parser and expander for Wikipedia, Wiktionary etc. dump files, with Lua execution support
-
nixos-unstable 0.4.96-unstable-2026-03-06
- nixpkgs-unstable 0.4.96-unstable-2026-03-06
- nixos-unstable-small 0.4.96-unstable-2026-03-06
pkgs.terraform-providers.buildkite_buildkite
None
pkgs.vscode-extensions.RoweWilsonFrederiskHolme.wikitext
Extension that helps users view and write MediaWiki's Wikitext files
Package maintainers
-
@mostlyobvious Paweł Pacana <pawel.pacana@gmail.com>
-
@jsoo1 John Soo <jsoo1@asu.edu>
-
@cbrxyz Cameron Brown <me@cbrxyz.com>
-
@techknowlogick techknowlogick <techknowlogick@gitea.com>
-
@zimbatm zimbatm <zimbatm@zimbatm.com>
-
@groodt Greg Roodt <groodt@gmail.com>
-
@jfroche Jean-François Roche <jfroche@pyxel.be>
-
@K900 Ilya K. <me@0upti.me>
-
@LunNova Luna Nova <nixpkgs-maintainer@lunnova.dev>
-
@mjm Matt Moriarity <matt@mattmoriarity.com>
-
@ilya-fedin Ilya Fedin <fedin-ilja2010@ya.ru>
-
@ttuegel Thomas Tuegel <ttuegel@mailbox.org>
-
@bkchr Bastian Köcher <nixos@kchr.de>
-
@SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com>
-
@NickCao Nick Cao <nickcao@nichi.co>
-
@nyanloutre Paul Trehiou <paul@nyanlout.re>
-
@FRidh Frederik Rietdijk <fridh@fridh.nl>
-
@peterhoeg Peter Hoeg <peter@hoeg.com>
-
@dramforever Vivian Wang <dramforever@live.com>
-
@Ben9986 Ben Carmichael <ben9986.unvmn@passinbox.com>
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>
-
@Steinhagen Viorel-Cătălin Răpițeanu <rapiteanu.catalin@gmail.com>
-
@theobori Théo Bori <theobori@disroot.org>