7.8 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Local (L)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Local (L)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
Activity log
- Created suggestion
Kite 1.2020.1119.0 - 'KiteService' Unquoted Service Path
Kite 1.2020.1119.0 contains an unquoted service path vulnerability in the KiteService Windows service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Kite\KiteService.exe' to inject malicious executables and escalate privileges on the system.
References
-
ExploitDB-49205 exploit
-
Vendor Homepage product
-
VulnCheck Advisory: Kite 1.2020.1119.0 - 'KiteService' Unquoted Service Path third-party-advisory
Affected products
- =<1.2020.1119.0
Matching in nixpkgs
pkgs.kitex
A high-performance and strong-extensibility Golang RPC framework
pkgs.kiterunner
Contextual content discovery tool
pkgs.buildkite-cli
Command line interface for Buildkite
pkgs.buildkite-agent
Build runner for buildkite.com
pkgs.kdePackages.kiten
Japanese Reference/Study Tool
pkgs.libsForQt5.krohnkite
Dynamic tiling extension for KWin
pkgs.kdePackages.krohnkite
Dynamic Tiling Extension for KWin 6
pkgs.libsForQt5.kitemviews
None
pkgs.kdePackages.kitemviews
KItemViews
pkgs.libsForQt5.kitemmodels
None
pkgs.buildkite-agent-metrics
Command-line tool (and Lambda) for collecting Buildkite agent metrics
pkgs.kdePackages.kitemmodels
KItemModels
pkgs.plasma5Packages.krohnkite
Dynamic tiling extension for KWin
pkgs.plasma5Packages.kitemviews
None
pkgs.plasma5Packages.kitemmodels
None
pkgs.buildkite-test-collector-rust
Rust adapter for Buildkite Test Analytics
pkgs.terraform-providers.buildkite
None
pkgs.haskellPackages.PenroseKiteDart
Library to explore Penrose's Kite and Dart Tilings
pkgs.python312Packages.wikitextparser
Simple parsing tool for MediaWiki's wikitext markup
pkgs.python313Packages.wikitextparser
Simple parsing tool for MediaWiki's wikitext markup
pkgs.terraform-providers.buildkite_buildkite
None
pkgs.vscode-extensions.RoweWilsonFrederiskHolme.wikitext
Extension that helps users view and write MediaWiki's Wikitext files
Package maintainers
-
@mostlyobvious Paweł Pacana <pawel.pacana@gmail.com>
-
@zimbatm zimbatm <zimbatm@zimbatm.com>
-
@techknowlogick techknowlogick <techknowlogick@gitea.com>
-
@jsoo1 John Soo <jsoo1@asu.edu>
-
@grahamc Graham Christensen <graham@grahamc.com>
-
@cole-h Cole Helbling <cole.e.helbling@outlook.com>
-
@groodt Greg Roodt <groodt@gmail.com>
-
@jfroche Jean-François Roche <jfroche@pyxel.be>
-
@mjm Matt Moriarity <matt@mattmoriarity.com>
-
@NickCao Nick Cao <nickcao@nichi.co>
-
@ilya-fedin Ilya Fedin <fedin-ilja2010@ya.ru>
-
@LunNova Luna Nova <nixpkgs-maintainer@lunnova.dev>
-
@SCOTT-HAMILTON Scott Hamilton <sgn.hamilton@protonmail.com>
-
@K900 Ilya K. <me@0upti.me>
-
@bkchr Bastian Köcher <nixos@kchr.de>
-
@peterhoeg Peter Hoeg <peter@hoeg.com>
-
@FRidh Frederik Rietdijk <fridh@fridh.nl>
-
@nyanloutre Paul Trehiou <paul@nyanlout.re>
-
@ttuegel Thomas Tuegel <ttuegel@mailbox.org>
-
@SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com>
-
@dramforever Vivian Wang <dramforever@live.com>
-
@Ben9986 Ben Carmichael <ben9986.unvmn@passinbox.com>
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>
-
@aaronjheng Aaron Jheng <wentworth@outlook.com>
-
@seqizz Gurkan Gur <seqizz@gmail.com>
-
@Steinhagen Viorel-Cătălin Răpițeanu <rapiteanu.catalin@gmail.com>