CVE-2023-34642

KioWare for Windows through v8.33 was discovered to contain an incomplete blacklist filter for blocked dialog boxes on Windows 10. This issue can allow attackers to open a file dialog box via the function showDirectoryPicker() which can then be used to open an unprivileged command prompt.
Configurations

Configuration 1 (hide)

cpe:2.3:a:kioware:kioware:*:*:*:*:*:windows:*:*

History

12 Dec 2024, 01:23

Type Values Removed Values Added
CWE CWE-78

Information

Published : 2023-06-19 05:15

Updated : 2024-12-12 01:23


NVD link : CVE-2023-34642

Mitre link : CVE-2023-34642

CVE.ORG link : CVE-2023-34642


JSON object : View

Products Affected

kioware

  • kioware
CWE
NVD-CWE-noinfo CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')