Vulnerability Description
KioWare through 8.33 on Windows sets KioScriptingUrlACL.AclActions.AllowHigh for the about:blank origin, which allows attackers to obtain SYSTEM access via KioUtils.Execute in JavaScript code.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kioware | Kioware | <= 8.33 |
Related Weaknesses (CWE)
References
- https://github.com/olnor18/writeup/tree/master/CVE/CVE-2022-44875ExploitThird Party Advisory
- https://www.kioware.com/versionhistory.aspx?pid=15Release Notes
- https://github.com/olnor18/writeup/tree/master/CVE/CVE-2022-44875ExploitThird Party Advisory
- https://www.kioware.com/versionhistory.aspx?pid=15Release Notes
FAQ
What is CVE-2022-44875?
CVE-2022-44875 is a vulnerability with a CVSS score of 5.4 (MEDIUM). KioWare through 8.33 on Windows sets KioScriptingUrlACL.AclActions.AllowHigh for the about:blank origin, which allows attackers to obtain SYSTEM access via KioUtils.Execute in JavaScript code.
How severe is CVE-2022-44875?
CVE-2022-44875 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-44875?
Check the references section above for vendor advisories and patch information. Affected products include: Kioware Kioware.