KioWare for Windows (versions all through 8.34) allows to escape the environment by downloading PDF files, which then by default are opened in an external PDF viewer. By using built-in functions of that viewer it is possible to launch a web browser, search through local files and, subsequently, launch any program with user privileges.
This Cyber News was published on www.tenable.com. Publication date: Wed, 15 May 2024 08:56:04 +0000