CVE-2024-3459

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published May 14, 2024

Summary

CVE-2024-3459 is a vulnerability affecting KioWare for Windows versions up to 8.34. This issue permits users to download PDF files within the application, which by default open in an external PDF viewer. Maliciously crafted PDFs can then exploit built-in functions of the viewer to launch a web browser, search local files, and execute any program with user privileges, effectively escaping the confined environment.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share