CVE-2023-36657: Critical severity opswat metadefender kiosk vulnerability
Published Sep 15, 2023
·Updated
An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. Built-in features of Windows (desktop shortcuts, narrator) can be abused for privilege escalation.
Affected Software
1 affected component
OPSWAT MetaDefender KIOSK>=4.5.0<=4.6.1.9996
Event History
Sep 15, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-36657?
The severity of CVE-2023-36657 is critical.
2
What is affected by CVE-2023-36657?
The affected software by CVE-2023-36657 is OPSWAT MetaDefender KIOSK version 4.6.1.9996 and earlier.
3
How can built-in features of Windows be abused for privilege escalation in CVE-2023-36657?
Built-in features of Windows, such as desktop shortcuts and narrator, can be abused for privilege escalation in CVE-2023-36657.
4
How can I fix CVE-2023-36657?
To fix CVE-2023-36657, update OPSWAT MetaDefender KIOSK to version 4.6.1.9997 or later, as specified in the release notes.
5
Where can I find more information about CVE-2023-36657?
More information about CVE-2023-36657 can be found in the OPSWAT MetaDefender KIOSK documentation and release notes.