CVE-2021-35230

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
22/10/2021
Last modified:
28/10/2021

Description

As a result of an unquoted service path vulnerability present in the Kiwi CatTools Installation Wizard, a local attacker could gain escalated privileges by inserting an executable into the path of the affected service or uninstall entry.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:solarwinds:kiwi_cattools:*:*:*:*:*:*:*:* 3.11.9 (excluding)