7.8 HIGH
- CVSS version: 3.1
- Attack vector (AV): LOCAL
- Attack complexity (AC): LOW
- Privileges required (PR): LOW
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): HIGH
- Availability impact (A): HIGH
Kite 1.2020.1119.0 - 'KiteService' Unquoted Service Path
Kite 1.2020.1119.0 contains an unquoted service path vulnerability in the KiteService Windows service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Kite\KiteService.exe' to inject malicious executables and escalate privileges on the system.
References
- ExploitDB-49205 exploit
- Vendor Homepage product
- VulnCheck Advisory: Kite 1.2020.1119.0 - 'KiteService' Unquoted Service Path third-party-advisory
Affected products
- =<1.2020.1119.0
Matching in nixpkgs
pkgs.kitex
A high-performance and strong-extensibility Golang RPC framework
pkgs.kiterunner
Contextual content discovery tool
pkgs.buildkite-cli
Command line interface for Buildkite
pkgs.buildkite-agent
Build runner for buildkite.com
pkgs.kdePackages.kiten
Japanese Reference/Study Tool
pkgs.libsForQt5.krohnkite
Dynamic tiling extension for KWin
pkgs.kdePackages.krohnkite
Dynamic Tiling Extension for KWin 6
pkgs.libsForQt5.kitemviews
None
pkgs.kdePackages.kitemviews
KItemViews
pkgs.libsForQt5.kitemmodels
None
pkgs.buildkite-agent-metrics
Command-line tool (and Lambda) for collecting Buildkite agent metrics
pkgs.kdePackages.kitemmodels
KItemModels
pkgs.plasma5Packages.krohnkite
Dynamic tiling extension for KWin
pkgs.plasma5Packages.kitemviews
None
pkgs.plasma5Packages.kitemmodels
None
pkgs.buildkite-test-collector-rust
Rust adapter for Buildkite Test Analytics
pkgs.terraform-providers.buildkite
None
pkgs.haskellPackages.PenroseKiteDart
Library to explore Penrose's Kite and Dart Tilings
pkgs.python312Packages.wikitextparser
Simple parsing tool for MediaWiki's wikitext markup
pkgs.python313Packages.wikitextparser
Simple parsing tool for MediaWiki's wikitext markup
pkgs.terraform-providers.buildkite_buildkite
None
pkgs.vscode-extensions.RoweWilsonFrederiskHolme.wikitext
Extension that helps users view and write MediaWiki's Wikitext files
Package maintainers
-
@mostlyobvious Paweł Pacana <pawel.pacana@gmail.com>
-
@zimbatm zimbatm <zimbatm@zimbatm.com>
-
@jsoo1 John Soo <jsoo1@asu.edu>
-
@techknowlogick techknowlogick <techknowlogick@gitea.com>
-
@grahamc Graham Christensen <graham@grahamc.com>
-
@cole-h Cole Helbling <cole.e.helbling@outlook.com>
-
@groodt Greg Roodt <groodt@gmail.com>
-
@jfroche Jean-François Roche <jfroche@pyxel.be>
-
@bkchr Bastian Köcher <nixos@kchr.de>
-
@mjm Matt Moriarity <matt@mattmoriarity.com>
-
@peterhoeg Peter Hoeg <peter@hoeg.com>
-
@NickCao Nick Cao <nickcao@nichi.co>
-
@ilya-fedin Ilya Fedin <fedin-ilja2010@ya.ru>
-
@LunNova Luna Nova <nixpkgs-maintainer@lunnova.dev>
-
@FRidh Frederik Rietdijk <fridh@fridh.nl>
-
@SCOTT-HAMILTON Scott Hamilton <sgn.hamilton@protonmail.com>
-
@nyanloutre Paul Trehiou <paul@nyanlout.re>
-
@ttuegel Thomas Tuegel <ttuegel@mailbox.org>
-
@SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com>
-
@K900 Ilya K. <me@0upti.me>
-
@dramforever Vivian Wang <dramforever@live.com>
-
@Ben9986 Ben Carmichael <ben9986.unvmn@passinbox.com>
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>
-
@aaronjheng Aaron Jheng <wentworth@outlook.com>
-
@seqizz Gurkan Gur <seqizz@gmail.com>
-
@Steinhagen Viorel-Cătălin Răpițeanu <rapiteanu.catalin@gmail.com>