CVE-2021-35230: Unquoted Path Vulnerability (SMB Login) in Kiwi CatTools
Published Oct 22, 2021
·Updated
As a result of an unquoted service path vulnerability present in the Kiwi CatTools Installation Wizard, a local attacker could gain escalated privileges by inserting an executable into the path of the affected service or uninstall entry.
Affected Software
1 affected component
SolarWinds Kiwi CatTools<3.11.9
Remediation
Information
SolarWinds advises Kiwi CatTools customers to upgrade to the latest version (3.11.9) once it becomes generally available.
Event History
Oct 22, 2021
CVE Published
via MITRE·11:19 AM
Data Sourced
via MITRE·11:19 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-35230?
CVE-2021-35230 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2021-35230?
To fix CVE-2021-35230, ensure that any affected versions of SolarWinds Kiwi CatTools are updated to the latest version.
3
What systems are affected by CVE-2021-35230?
CVE-2021-35230 affects all versions of SolarWinds Kiwi CatTools up to and including 3.11.9.
4
Can CVE-2021-35230 be exploited remotely?
No, CVE-2021-35230 can only be exploited locally by an attacker with access to the system.
5
What type of vulnerability is CVE-2021-35230?
CVE-2021-35230 is an unquoted service path vulnerability that can lead to privilege escalation.