Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 18 May 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 16 May 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kite
Kite kite |
|
| Vendors & Products |
Kite
Kite kite |
Sat, 16 May 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kite 4.2.0.1 U1 contains an unquoted service path vulnerability in the KiteService Windows service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious executable in the Program Files directory to be executed with LocalSystem privileges when the service starts. | |
| Title | Kite 4.2.0.1 U1 Unquoted Service Path Privilege Escalation | |
| Weaknesses | CWE-428 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-18T12:40:56.121Z
Reserved: 2026-05-16T14:54:10.515Z
Link: CVE-2020-37247
Updated: 2026-05-18T12:40:45.477Z
Status : Deferred
Published: 2026-05-16T16:16:21.123
Modified: 2026-06-17T03:17:21.443
Link: CVE-2020-37247
No data.
OpenCVE Enrichment
Updated: 2026-05-16T17:00:13Z