PT-2026-4782 · Kite · Kite

Ismael Nava

·

Published

2026-01-26

·

Updated

2026-01-26

·

CVE-2020-36958

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kite version 1.2020.1119.0
Description The KiteService Windows service contains an unquoted service path issue. Local attackers can exploit the unquoted path in 'C:Program FilesKiteKiteService.exe' to inject malicious executables, potentially leading to arbitrary code execution and privilege escalation on the system.
Recommendations For version 1.2020.1119.0, ensure the service path for KiteService is properly quoted to prevent the execution of malicious binaries.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2020-36958

Affected Products

Kite