8.5 HIGH
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Local (L)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): High (H)
- Vulnerable System Impact Integrity (VI): High (H)
- Vulnerable System Impact Availability (VA): High (H)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Local (L)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): High (H)
- Modified Vulnerable System Impact Integrity (MVI): High (H)
- Modified Vulnerable System Impact Availability (MVA): High (H)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse dismissed (not in Nixpkgs)
Kite 4.2.0.1 U1 Unquoted Service Path Privilege Escalation
Kite 4.2.0.1 U1 contains an unquoted service path vulnerability in the KiteService Windows service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious executable in the Program Files directory to be executed with LocalSystem privileges when the service starts.
References
-
ExploitDB-50975 exploit
-
Official Product Homepage product
-
VulnCheck Advisory: Kite 4.2.0.1 U1 Unquoted Service Path Privilege Escalation third-party-advisory
Affected products
- ==4.2.0.1 U1
Matching in nixpkgs
pkgs.kitex
High-performance and strong-extensibility Golang RPC framework
pkgs.kiterunner
Contextual content discovery tool
pkgs.buildkite-cli
Command line interface for Buildkite
pkgs.buildkite-agent
Build runner for buildkite.com
pkgs.kdePackages.kiten
Japanese Reference/Study Tool
pkgs.kdePackages.krohnkite
Dynamic Tiling Extension for KWin 6
pkgs.libsForQt5.kitemviews
None
pkgs.kdePackages.kitemviews
KItemViews
pkgs.libsForQt5.kitemmodels
None
pkgs.buildkite-agent-metrics
Command-line tool (and Lambda) for collecting Buildkite agent metrics
pkgs.kdePackages.kitemmodels
KItemModels
pkgs.plasma5Packages.kitemviews
None
pkgs.plasma5Packages.kitemmodels
None
pkgs.buildkite-test-collector-rust
Rust adapter for Buildkite Test Analytics
pkgs.terraform-providers.buildkite
None
pkgs.haskellPackages.PenroseKiteDart
Library to explore Penrose's Kite and Dart Tilings
pkgs.python312Packages.wikitextparser
Simple parsing tool for MediaWiki's wikitext markup
pkgs.python313Packages.wikitextparser
Simple parsing tool for MediaWiki's wikitext markup
pkgs.python314Packages.wikitextparser
Simple parsing tool for MediaWiki's wikitext markup
pkgs.python313Packages.wikitextprocessor
Parser and expander for Wikipedia, Wiktionary etc. dump files, with Lua execution support
-
nixos-unstable 0.4.96-unstable-2026-03-06
- nixpkgs-unstable 0.4.96-unstable-2026-03-06
- nixos-unstable-small 0.4.96-unstable-2026-03-06
pkgs.python314Packages.wikitextprocessor
Parser and expander for Wikipedia, Wiktionary etc. dump files, with Lua execution support
-
nixos-unstable 0.4.96-unstable-2026-03-06
- nixpkgs-unstable 0.4.96-unstable-2026-03-06
- nixos-unstable-small 0.4.96-unstable-2026-03-06
pkgs.terraform-providers.buildkite_buildkite
None
Package maintainers
-
@jsoo1 John Soo <jsoo1@asu.edu>
-
@techknowlogick techknowlogick <techknowlogick@gitea.com>
-
@zimbatm zimbatm <zimbatm@zimbatm.com>
-
@mostlyobvious Paweł Pacana <pawel.pacana@gmail.com>
-
@cole-h Cole Helbling <cole.e.helbling@outlook.com>
-
@grahamc Graham Christensen <graham@grahamc.com>
-
@groodt Greg Roodt <groodt@gmail.com>
-
@jfroche Jean-François Roche <jfroche@pyxel.be>
-
@ilya-fedin Ilya Fedin <fedin-ilja2010@ya.ru>
-
@NickCao Nick Cao <nickcao@nichi.co>
-
@nyanloutre Paul Trehiou <paul@nyanlout.re>
-
@LunNova Luna Nova <nixpkgs-maintainer@lunnova.dev>
-
@FRidh Frederik Rietdijk <fridh@fridh.nl>
-
@peterhoeg Peter Hoeg <peter@hoeg.com>
-
@mjm Matt Moriarity <matt@mattmoriarity.com>
-
@K900 Ilya K. <me@0upti.me>
-
@bkchr Bastian Köcher <nixos@kchr.de>
-
@ttuegel Thomas Tuegel <ttuegel@mailbox.org>
-
@SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com>
-
@Ben9986 Ben Carmichael <ben9986.unvmn@passinbox.com>
-
@dramforever Vivian Wang <dramforever@live.com>
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>
-
@Steinhagen Viorel-Cătălin Răpițeanu <rapiteanu.catalin@gmail.com>
-
@theobori Théo Bori <theobori@disroot.org>