KioWare through 8.33 on Windows sets KioScriptingUrlACL.AclActions.AllowHigh for the about:blank origin, which allows attackers to obtain SYSTEM access via KioUtils.Execute in JavaScript code.
No PoCs from references.
- https://github.com/AesirSec/CVE-2022-44875-Test
- https://github.com/c0d30d1n/CVE-2022-44875-Test
- https://github.com/nomi-sec/PoC-in-GitHub