SB2021110220 - Unquoted Search Path or Element in SolarWinds Kiwi CatTools
Published: November 2, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Unquoted Search Path or Element (CVE-ID: CVE-2021-35230)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to an unquoted service path in the Installation Wizard. A local administrator can insert an executable into the path of the affected service and gain elevated privileges on the target system.
Remediation
Install update from vendor's website.