Kioware

Kioware

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.01%
  • Veröffentlicht 14.05.2024 15:41:13
  • Zuletzt bearbeitet 12.02.2025 15:37:59

KioWare for Windows (versions all through 8.35) allows to brute force the PIN number, which protects the application from being closed, as there are no mechanisms preventing a user from excessively guessing the number.

  • EPSS 0.08%
  • Veröffentlicht 14.05.2024 15:41:12
  • Zuletzt bearbeitet 12.02.2025 01:48:00

KioWare for Windows (versions all through 8.34) allows to escape the environment by downloading PDF files, which then by default are opened in an external PDF viewer. By using built-in functions of that viewer it is possible to launch a web browser, ...

  • EPSS 0.05%
  • Veröffentlicht 14.05.2024 15:41:12
  • Zuletzt bearbeitet 12.02.2025 15:36:15

In KioWare for Windows (versions all through 8.34) it is possible to exit this software and use other already opened applications utilizing a short time window before the forced automatic logout occurs. Then, by using some built-in function of these ...

  • EPSS 0.05%
  • Veröffentlicht 19.06.2023 05:15:09
  • Zuletzt bearbeitet 12.12.2024 01:23:47

KioWare for Windows through v8.33 was discovered to contain an incomplete blacklist filter for blocked dialog boxes on Windows 10. This issue can allow attackers to open a file dialog box via the function window.print() which can then be used to open...

  • EPSS 0.06%
  • Veröffentlicht 19.06.2023 05:15:09
  • Zuletzt bearbeitet 12.12.2024 01:23:47

KioWare for Windows through v8.33 was discovered to contain an incomplete blacklist filter for blocked dialog boxes on Windows 10. This issue can allow attackers to open a file dialog box via the function showDirectoryPicker() which can then be used ...

Exploit
  • EPSS 1.47%
  • Veröffentlicht 06.03.2023 05:15:11
  • Zuletzt bearbeitet 06.03.2025 21:15:12

KioWare through 8.33 on Windows sets KioScriptingUrlACL.AclActions.AllowHigh for the about:blank origin, which allows attackers to obtain SYSTEM access via KioUtils.Execute in JavaScript code.