KDE Kleopatra Local Privilege Escalation Vulnerability on Windows
Vulnerability
A local privilege escalation vulnerability has been identified in KDE Kleopatra versions prior to 26.08.0 on Windows. The issue arises from a flaw in the application's instance management mechanism, KUniqueService, which fails to properly restrict multiple instances from running simultaneously. This vulnerability allows local users to gain the privileges of the Kleopatra user.
Impact
Exploitation of this vulnerability could lead to unauthorized access to the privileges of the Kleopatra user, potentially allowing a local attacker to escalate privileges to full administrator rights.
Remediation
Users are advised to update to KDE Kleopatra version 26.08.0 or later. If an immediate update is not possible, affected users should avoid running Kleopatra as an administrator and be cautious on Windows systems with untrusted users or software.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
