Medium severity6.7NVD Advisory· Published Oct 25, 2021· Updated Jun 17, 2026
CVE-2021-35231
CVE-2021-35231
Description
As a result of an unquoted service path vulnerability present in the Kiwi Syslog Server Installation Wizard, a local attacker could gain escalated privileges by inserting an executable into the path of the affected service or uninstall entry. Example vulnerable path: "Computer\HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Kiwi Syslog Server\Parameters\Application".
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:solarwinds:kiwi_syslog_server:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:solarwinds:kiwi_syslog_server:*:*:*:*:*:*:*:*range: <9.8
- (no CPE)
- (no CPE)range: 9.7.2 and previous versions
Patches
Vulnerability mechanics
References
2- documentation.solarwinds.com/en/success_center/kss/content/release_notes/kss_9-8_release_notes.htmnvdRelease NotesVendor Advisory
- www.solarwinds.com/trust-center/security-advisories/cve-2021-35231nvdVendor Advisory
News mentions
0No linked articles in our index yet.