Vulnerability Allows Escape from Environment via PDF Files
CVE-2024-3459
7.8HIGH
What is CVE-2024-3459?
A vulnerability in KioWare for Windows allows for an escape from the secure environment through the handling of PDF files. This flaw is present in all versions up to 8.34, where downloaded PDF files are launched in an external viewer. The external viewer has built-in capabilities that permit users to initiate a web browser, access local files, and potentially execute any program with the same user privileges as the current session. This issue underscores significant security implications for users and requires immediate attention to mitigate associated risks.
Affected Version(s)
Kioware Windows 0 <= 8.34