Search

Find a vulnerability

Search criteria

    157 vulnerabilities by Kaspersky

    CERTFR-2026-AVI-1101

    Vulnerability from certfr_avis - Published: 2026-09-01 - Updated: 2026-09-01

    Une vulnérabilité a été découverte dans Kaspersky Endpoint Security Windows. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    Kaspersky Endpoint Security Endpoint Security Windows versions 14.0 et 14.1 sans la mise à jour du 30 aout 2026
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Endpoint Security Windows versions 14.0 et 14.1 sans la mise \u00e0 jour du 30 aout 2026 ",
          "product": {
            "name": "Endpoint Security",
            "vendor": {
              "name": "Kaspersky",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [],
      "initial_release_date": "2026-09-01T00:00:00",
      "last_revision_date": "2026-09-01T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-1101",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-09-01T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans Kaspersky Endpoint Security Windows. Elle permet \u00e0 un attaquant de provoquer un contournement de la politique de s\u00e9curit\u00e9.",
      "title": "Vuln\u00e9rabilit\u00e9 dans Kaspersky Endpoint Security Windows",
      "vendor_advisories": [
        {
          "published_at": "2026-08-31",
          "title": "Bulletin de s\u00e9curit\u00e9 Kaspersky 12430#310826",
          "url": "https://support.kaspersky.com/vulnerability/list-of-advisories/12430#310826"
        }
      ]
    }

    CERTFR-2026-AVI-0668

    Vulnerability from certfr_avis - Published: 2026-06-01 - Updated: 2026-06-01

    Une vulnérabilité a été découverte dans Kaspersky Anti Targeted Attack Platform. Elle permet à un attaquant de provoquer un déni de service à distance.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    Kaspersky Anti Targeted Attack Platform Anti Targeted Attack Server versions 8.0.x antérieures à 8.0.1
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Anti Targeted Attack Server versions 8.0.x ant\u00e9rieures \u00e0 8.0.1",
          "product": {
            "name": "Anti Targeted Attack Platform",
            "vendor": {
              "name": "Kaspersky",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-31932",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-31932"
        }
      ],
      "initial_release_date": "2026-06-01T00:00:00",
      "last_revision_date": "2026-06-01T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-0668",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-06-01T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans Kaspersky Anti Targeted Attack Platform. Elle permet \u00e0 un attaquant de provoquer un d\u00e9ni de service \u00e0 distance.",
      "title": "Vuln\u00e9rabilit\u00e9 dans Kaspersky Anti Targeted Attack Platform",
      "vendor_advisories": [
        {
          "published_at": "2026-05-29",
          "title": "Bulletin de s\u00e9curit\u00e9 Kaspersky 12430#290526",
          "url": "https://support.kaspersky.com/vulnerability/list-of-advisories/12430#290526"
        }
      ]
    }

    CERTFR-2026-AVI-0648

    Vulnerability from certfr_avis - Published: 2026-05-27 - Updated: 2026-05-27

    De multiples vulnérabilités ont été découvertes dans Kaspersky Anti Targeted Attack Platform. Elles permettent à un attaquant de provoquer une injection de code indirecte à distance (XSS).

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    Kaspersky Anti Targeted Attack Server Anti Targeted Attack Platform versions anterieures à 7.1.7
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Anti Targeted Attack Platform versions anterieures \u00e0 7.1.7",
          "product": {
            "name": "Anti Targeted Attack Server",
            "vendor": {
              "name": "Kaspersky",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-28350",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-28350"
        },
        {
          "name": "CVE-2026-28348",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-28348"
        }
      ],
      "initial_release_date": "2026-05-27T00:00:00",
      "last_revision_date": "2026-05-27T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-0648",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-05-27T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Injection de code indirecte \u00e0 distance (XSS)"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans Kaspersky Anti Targeted Attack Platform. Elles permettent \u00e0 un attaquant de provoquer une injection de code indirecte \u00e0 distance (XSS).",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans Kaspersky Anti Targeted Attack Platform",
      "vendor_advisories": [
        {
          "published_at": "2026-05-26",
          "title": "Bulletin de s\u00e9curit\u00e9 Kaspersky 12430#260526",
          "url": "https://support.kaspersky.com/vulnerability/list-of-advisories/12430#260526"
        }
      ]
    }

    CERTFR-2025-AVI-1039

    Vulnerability from certfr_avis - Published: 2025-11-25 - Updated: 2025-11-25

    Une vulnérabilité a été découverte dans Kaspersky Security Center. Elle permet à un attaquant de provoquer une atteinte à l'intégrité des données.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    Kaspersky Security Center Security Center pour Windows sans le correctif de sécurité
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Security Center pour Windows sans le correctif de s\u00e9curit\u00e9",
          "product": {
            "name": "Security Center",
            "vendor": {
              "name": "Kaspersky",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [],
      "initial_release_date": "2025-11-25T00:00:00",
      "last_revision_date": "2025-11-25T00:00:00",
      "links": [],
      "reference": "CERTFR-2025-AVI-1039",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2025-11-25T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans Kaspersky Security Center. Elle permet \u00e0 un attaquant de provoquer une atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es.",
      "title": "Vuln\u00e9rabilit\u00e9 dans Kaspersky Security Center",
      "vendor_advisories": [
        {
          "published_at": "2025-11-24",
          "title": "Bulletin de s\u00e9curit\u00e9 Kaspersky 12430#241125",
          "url": "https://support.kaspersky.com/vulnerability/list-of-advisories/12430#241125"
        }
      ]
    }

    CERTFR-2025-AVI-0262

    Vulnerability from certfr_avis - Published: 2025-04-02 - Updated: 2025-04-02

    De multiples vulnérabilités ont été découvertes dans les produits Kaspersky. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    Kaspersky IoT Secure Gateway Network Protector IoT Secure Gateway Network Protector version 3.1.0.130 sans les derniers correctifs de sécurité
    Kaspersky Anti Targeted Attack Server Anti Targeted Attack Server versions 6.x antérieures à 6.0.4
    Kaspersky Anti Targeted Attack Server Anti Targeted Attack Server versions 7.x antérieures à 7.0.3
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "IoT Secure Gateway Network Protector version 3.1.0.130 sans les derniers correctifs de s\u00e9curit\u00e9",
          "product": {
            "name": "IoT Secure Gateway Network Protector",
            "vendor": {
              "name": "Kaspersky",
              "scada": false
            }
          }
        },
        {
          "description": "Anti Targeted Attack Server versions 6.x ant\u00e9rieures \u00e0 6.0.4",
          "product": {
            "name": "Anti Targeted Attack Server",
            "vendor": {
              "name": "Kaspersky",
              "scada": false
            }
          }
        },
        {
          "description": "Anti Targeted Attack Server versions 7.x ant\u00e9rieures \u00e0 7.0.3",
          "product": {
            "name": "Anti Targeted Attack Server",
            "vendor": {
              "name": "Kaspersky",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2024-55629",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-55629"
        },
        {
          "name": "CVE-2024-55605",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-55605"
        },
        {
          "name": "CVE-2024-55628",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-55628"
        },
        {
          "name": "CVE-2024-55627",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-55627"
        }
      ],
      "initial_release_date": "2025-04-02T00:00:00",
      "last_revision_date": "2025-04-02T00:00:00",
      "links": [],
      "reference": "CERTFR-2025-AVI-0262",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2025-04-02T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits Kaspersky. Elles permettent \u00e0 un attaquant de provoquer un probl\u00e8me de s\u00e9curit\u00e9 non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits Kaspersky",
      "vendor_advisories": [
        {
          "published_at": "2025-04-01",
          "title": "Bulletin de s\u00e9curit\u00e9 Kaspersky 12430#010425",
          "url": "https://support.kaspersky.com/vulnerability/list-of-advisories/12430#010425"
        }
      ]
    }

    CVE-2025-64984 (GCVE-0-2025-64984)

    Vulnerability from nvd – Published: 2025-11-20 06:53 – Updated: 2025-11-20 15:42
    VLAI
    Summary
    Kaspersky has fixed a security issue in Kaspersky Endpoint Security for Linux (any version with anti-virus databases prior to 18.11.2025), Kaspersky Industrial CyberSecurity for Linux Nodes (any version with anti-virus databases prior to 18.11.2025), and Kaspersky Endpoint Security for Mac (12.0.0.325, 12.1.0.553, and 12.2.0.694 with anti-virus databases prior to 18.11.2025) that could have allowed a reflected XSS attack to be carried out by an attacker using phishing techniques.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-11-20 15:42 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    References
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-64984",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-11-20T15:42:09.290134Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-11-20T15:42:14.162Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "MacOS"
              ],
              "product": "Kaspersky Endpoint Security",
              "vendor": "Kaspersky",
              "versions": [
                {
                  "status": "affected",
                  "version": "12.0.0.325"
                },
                {
                  "status": "affected",
                  "version": "12.1.0.553"
                },
                {
                  "status": "unknown",
                  "version": "12.2.0.694"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "platforms": [
                "Linux"
              ],
              "product": "Kaspersky Endpoint Security",
              "vendor": "Kaspersky"
            },
            {
              "defaultStatus": "unknown",
              "platforms": [
                "Linux"
              ],
              "product": "Kaspersky Industrial CyberSecurity for Linux Nodes",
              "vendor": "Kaspersky"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Kaspersky has fixed a security issue in Kaspersky Endpoint Security for Linux (any version with anti-virus databases prior to 18.11.2025), Kaspersky Industrial CyberSecurity for Linux Nodes (any version with anti-virus databases prior to 18.11.2025), and Kaspersky Endpoint Security for Mac (12.0.0.325, 12.1.0.553, and 12.2.0.694 with anti-virus databases prior to 18.11.2025) that could have allowed a reflected XSS attack to be carried out by an attacker using phishing techniques."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.1,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                "version": "3.1"
              },
              "cvssV4_0": {
                "baseScore": 5.1,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
                "version": "4.0"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79: Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-11-20T06:53:39.628Z",
            "orgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
            "shortName": "Kaspersky"
          },
          "references": [
            {
              "name": "Advisory issued on November 18, 2025",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://support.kaspersky.com/vulnerability/list-of-advisories/12430#181125"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Users should update anti-virus databases to use at least the version from 11/18/2025."
            },
            {
              "lang": "en",
              "value": "Users of Kaspersky Endpoint Security for Mac versions 12.0.0.325 and 12.1.0.553 are recommended to update the application to version 12.2.0.694 with the latest version of the anti-virus databases."
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2025-11-18T00:00:00.000Z",
              "value": "Advisory published by Kaspersky"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
        "assignerShortName": "Kaspersky",
        "cveId": "CVE-2025-64984",
        "datePublished": "2025-11-20T06:53:39.628Z",
        "dateReserved": "2025-11-12T07:42:11.731Z",
        "dateUpdated": "2025-11-20T15:42:14.162Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-13614 (GCVE-0-2024-13614)

    Vulnerability from nvd – Published: 2025-02-06 16:13 – Updated: 2025-02-12 19:51
    VLAI
    Summary
    Kaspersky has fixed a security issue in Kaspersky Anti-Virus SDK for Windows, Kaspersky Security for Virtualization Light Agent, Kaspersky Endpoint Security for Windows, Kaspersky Small Office Security, Kaspersky for Windows (Standard, Plus, Premium), Kaspersky Free, Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Security Cloud, Kaspersky Safe Kids, Kaspersky Anti-Ransomware Tool that could allow an authenticated attacker to write data to a limited area outside the allocated kernel memory buffer. The fix was installed automatically for all Kaspersky Endpoint products.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-02-06 16:34 UTC
    CWE
    • CWE-190 - Integer Overflow or Wraparound
    References
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-13614",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-02-06T16:34:12.660585Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-02-12T19:51:09.532Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Kaspersky Anti-Virus SDK for Windows",
              "vendor": "Kaspersky",
              "versions": [
                {
                  "lessThanOrEqual": "8.10.1.1943",
                  "status": "affected",
                  "version": "8.10.1.1943",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "8.10.1.1943 CF",
                  "status": "affected",
                  "version": "8.10.1.1943 CF",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Kaspersky Security for Virtualization Light Agent",
              "vendor": "Kaspersky",
              "versions": [
                {
                  "lessThan": "5.2.27.319",
                  "status": "affected",
                  "version": "5.2",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "5.2.27.319",
                  "status": "unknown",
                  "version": "5.2.27.319",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Kaspersky Endpoint Security for Windows",
              "vendor": "Kaspersky"
            },
            {
              "defaultStatus": "unknown",
              "product": "Kaspersky Small Office Security",
              "vendor": "Kaspersky"
            },
            {
              "defaultStatus": "unknown",
              "product": "Kaspersky for Windows (Standard, Plus, Premium)",
              "vendor": "Kaspersky"
            },
            {
              "defaultStatus": "unknown",
              "product": "Kaspersky Free",
              "vendor": "Kaspersky"
            },
            {
              "defaultStatus": "unknown",
              "product": "Kaspersky Anti-Virus",
              "vendor": "Kaspersky"
            },
            {
              "defaultStatus": "unknown",
              "product": "Kaspersky Internet Security",
              "vendor": "Kaspersky"
            },
            {
              "defaultStatus": "unknown",
              "product": "Kaspersky Security Cloud",
              "vendor": "Kaspersky"
            },
            {
              "defaultStatus": "unknown",
              "product": "Kaspersky Safe Kids",
              "vendor": "Kaspersky"
            },
            {
              "defaultStatus": "unknown",
              "product": "Kaspersky Anti-Ransomware Tool",
              "vendor": "Kaspersky"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Florian Schweins"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Kaspersky has fixed a security issue in Kaspersky Anti-Virus SDK for Windows, Kaspersky Security for Virtualization Light Agent, Kaspersky Endpoint Security for Windows, Kaspersky Small Office Security, Kaspersky for Windows (Standard, Plus, Premium), Kaspersky Free, Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Security Cloud, Kaspersky Safe Kids, Kaspersky Anti-Ransomware Tool that could allow an authenticated attacker to write data to a limited area outside the allocated kernel memory buffer. The fix was installed automatically for all Kaspersky Endpoint products."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "value": "There have been no recorded attempts to exploit this issue in the wild."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-190",
                  "description": "CWE-190: Integer Overflow or Wraparound",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-02-06T16:16:54.229Z",
            "orgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
            "shortName": "Kaspersky"
          },
          "references": [
            {
              "name": "Advisory issued on February 6, 2025",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://support.kaspersky.com/vulnerability/list-of-advisories/12430#060225"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "To fix the vulnerability, upgrade the KAV SDK for Windows to the following version: Kaspersky Anti-Virus Software Development Kit 8 Level 3 v. 8.10.2.2098. Contact your Technical Account Manager to obtain the necessary instructions."
            },
            {
              "lang": "en",
              "value": "Install Kaspersky Security for Virtualization Light Agent 5.2.27.319 (with Kaspersky Security Components Installation Wizard 5.2.1.4005) or newer using the following url: https://www.kaspersky.com/small-to-medium-business-security/downloads/virtualization-hybrid-cloud"
            },
            {
              "lang": "en",
              "value": "The fix was installed automatically for Kaspersky Endpoint Security for Windows. To check for the fix, check the antivirus database update date, it should be November 6, 2024 or newer."
            },
            {
              "lang": "en",
              "value": "The fix was installed automatically for Kaspersky Small Office Security. To check for the fix, check the antivirus database update date, it should be November 6, 2024 or newer."
            },
            {
              "lang": "en",
              "value": "The fix was installed automatically for Kaspersky for Windows (Standard, Plus, Premium). To check for the fix, check the antivirus database update date, it should be November 6, 2024 or newer."
            },
            {
              "lang": "en",
              "value": "The fix was installed automatically for Kaspersky Free. To check for the fix, check the antivirus database update date, it should be November 6, 2024 or newer."
            },
            {
              "lang": "en",
              "value": "The fix was installed automatically for Kaspersky Anti-Virus. To check for the fix, check the antivirus database update date, it should be November 6, 2024 or newer."
            },
            {
              "lang": "en",
              "value": "The fix was installed automatically for Kaspersky Internet Security. To check for the fix, check the antivirus database update date, it should be November 6, 2024 or newer."
            },
            {
              "lang": "en",
              "value": "The fix was installed automatically for Kaspersky Security Cloud. To check for the fix, check the antivirus database update date, it should be November 6, 2024 or newer."
            },
            {
              "lang": "en",
              "value": "The fix was installed automatically for Kaspersky Safe Kids. To check for the fix, check the antivirus database update date, it should be November 6, 2024 or newer."
            },
            {
              "lang": "en",
              "value": "The fix was installed automatically for Kaspersky Anti-Ransomware Tool. To check for the fix, check the antivirus database update date, it should be November 6, 2024 or newer."
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2025-02-06T00:00:00.000Z",
              "value": "Advisory published by Kaspersky"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
        "assignerShortName": "Kaspersky",
        "cveId": "CVE-2024-13614",
        "datePublished": "2025-02-06T16:13:08.173Z",
        "dateReserved": "2025-01-22T06:31:25.425Z",
        "dateUpdated": "2025-02-12T19:51:09.532Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-23349 (GCVE-0-2023-23349)

    Vulnerability from nvd – Published: 2024-03-22 16:15 – Updated: 2025-04-10 20:10
    VLAI
    Summary
    Kaspersky has fixed a security issue in Kaspersky Password Manager (KPM) for Windows that allowed a local user to recover the auto-filled credentials from a memory dump when the KPM extension for Google Chrome is used. To exploit the issue, an attacker must trick a user into visiting a login form of a website with the saved credentials, and the KPM extension must autofill these credentials. The attacker must then launch a malware module to steal those specific credentials.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-03-25 16:49 UTC
    CWE
    • CWE-316 - Cleartext Storage of Sensitive Information in Memory
    References
    Impacted products
    Vendor Product Version
    Kaspersky Kaspersky Password Manager for Windows Affected: * , < 24.0.0.427 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-23349",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-03-25T16:49:20.375552Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-10T20:10:58.369Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T10:28:40.854Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "Advisory issued on March 18, 2024",
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://support.kaspersky.com/vulnerability/list-of-advisories/12430#180324"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Kaspersky Password Manager for Windows",
              "vendor": "Kaspersky",
              "versions": [
                {
                  "lessThan": "24.0.0.427",
                  "status": "affected",
                  "version": "*",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Efstratios Chatzoglou"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Zisis Tsiatsikas"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Vyron Kampourakis"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Kaspersky has fixed a security issue in Kaspersky Password Manager (KPM) for Windows that allowed a local user to recover the auto-filled credentials from a memory dump when the KPM extension for Google Chrome is used. To exploit the issue, an attacker must trick a user into visiting a login form of a website with the saved credentials, and the KPM extension must autofill these credentials. The attacker must then launch a malware module to steal those specific credentials."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "LOCAL",
                "availabilityImpact": "NONE",
                "baseScore": 2.2,
                "baseSeverity": "LOW",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-316",
                  "description": "CWE-316: Cleartext Storage of Sensitive Information in Memory",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-03-27T11:51:13.706Z",
            "orgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
            "shortName": "Kaspersky"
          },
          "references": [
            {
              "name": "Advisory issued on March 18, 2024",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://support.kaspersky.com/vulnerability/list-of-advisories/12430#180324"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Install Kaspersky Password Manager (KPM) version 24.0.0.427 or later using the following url: https://support.kaspersky.com/help/KPM/Win24.0/en-US/85241.htm"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2024-03-18T00:00:00.000Z",
              "value": "Advisory published by Kaspersky"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
        "assignerShortName": "Kaspersky",
        "cveId": "CVE-2023-23349",
        "datePublished": "2024-03-22T16:15:55.200Z",
        "dateReserved": "2023-01-11T20:11:14.512Z",
        "dateUpdated": "2025-04-10T20:10:58.369Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-1619 (GCVE-0-2024-1619)

    Vulnerability from nvd – Published: 2024-02-29 09:22 – Updated: 2024-08-01 18:48
    VLAI
    Summary
    Kaspersky has fixed a security issue in the Kaspersky Security 8.0 for Linux Mail Server. The issue was that an attacker could potentially force an administrator to click on a malicious link to perform unauthorized actions.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-03-11 16:14 UTC
    CWE
    • CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
    References
    Impacted products
    Vendor Product Version
    Kaspersky Kaspersky Security for Linux Mail Server 8 Affected: * , < 8.0.3.30 Security Patch A (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-1619",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-03-11T16:14:26.090266Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-04T18:00:28.058Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T18:48:20.684Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "Advisory issued on February 1, 2024",
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://support.kaspersky.com/vulnerability/list-of-advisories/12430#010224"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Kaspersky Security for Linux Mail Server 8",
              "vendor": "Kaspersky",
              "versions": [
                {
                  "lessThan": "8.0.3.30 Security Patch A",
                  "status": "affected",
                  "version": "*",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Adrian Tiron"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Bogdan Tiron"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Kaspersky has fixed a security issue in the Kaspersky Security 8.0 for Linux Mail Server. The issue was that an attacker could potentially force an administrator to click on a malicious link to perform unauthorized actions."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.1,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-74",
                  "description": "CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component (\u0027Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-02-29T09:22:03.588Z",
            "orgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
            "shortName": "Kaspersky"
          },
          "references": [
            {
              "name": "Advisory issued on February 1, 2024",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://support.kaspersky.com/vulnerability/list-of-advisories/12430#010224"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Install version 8.0.3.30 Security Patch A of Kaspersky Security 8.0 for Linux Mail Server."
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2024-02-01T00:00:00.000Z",
              "value": "Advisory published by Kaspersky"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
        "assignerShortName": "Kaspersky",
        "cveId": "CVE-2024-1619",
        "datePublished": "2024-02-29T09:22:03.588Z",
        "dateReserved": "2024-02-19T08:38:14.449Z",
        "dateUpdated": "2024-08-01T18:48:20.684Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-27535 (GCVE-0-2022-27535)

    Vulnerability from nvd – Published: 2022-08-05 16:47 – Updated: 2024-08-03 05:32
    VLAI
    Summary
    Kaspersky VPN Secure Connection for Windows version up to 21.5 was vulnerable to arbitrary file deletion via abuse of its 'Delete All Service Data And Reports' feature by the local authenticated attacker.
    Severity
    No CVSS data available.
    CWE
    • Local Privilege Escalation (LPE)
    Impacted products
    Vendor Product Version
    n/a Kaspersky VPN Secure Connection for Windows Affected: prior to 21.6
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T05:32:59.299Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#050822"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.synopsys.com/blogs/software-security/cyrc-advisory-kasperksy-vpn-microsoft-windows/"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://forum.kaspersky.com/topic/kaspersky-statement-on-cve-2022-27535-26742/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Kaspersky VPN Secure Connection for Windows",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "prior to 21.6"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Kaspersky VPN Secure Connection for Windows version up to 21.5 was vulnerable to arbitrary file deletion via abuse of its \u0027Delete All Service Data And Reports\u0027 feature by the local authenticated attacker."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Local Privilege Escalation (LPE)",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-08-09T19:55:41.000Z",
            "orgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
            "shortName": "Kaspersky"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#050822"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.synopsys.com/blogs/software-security/cyrc-advisory-kasperksy-vpn-microsoft-windows/"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://forum.kaspersky.com/topic/kaspersky-statement-on-cve-2022-27535-26742/"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vulnerability@kaspersky.com",
              "ID": "CVE-2022-27535",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Kaspersky VPN Secure Connection for Windows",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "prior to 21.6"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Kaspersky VPN Secure Connection for Windows version up to 21.5 was vulnerable to arbitrary file deletion via abuse of its \u0027Delete All Service Data And Reports\u0027 feature by the local authenticated attacker."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Local Privilege Escalation (LPE)"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#050822",
                  "refsource": "MISC",
                  "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#050822"
                },
                {
                  "name": "https://www.synopsys.com/blogs/software-security/cyrc-advisory-kasperksy-vpn-microsoft-windows/",
                  "refsource": "MISC",
                  "url": "https://www.synopsys.com/blogs/software-security/cyrc-advisory-kasperksy-vpn-microsoft-windows/"
                },
                {
                  "name": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#050822",
                  "refsource": "MISC",
                  "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#050822"
                },
                {
                  "name": "https://forum.kaspersky.com/topic/kaspersky-statement-on-cve-2022-27535-26742/",
                  "refsource": "MISC",
                  "url": "https://forum.kaspersky.com/topic/kaspersky-statement-on-cve-2022-27535-26742/"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
        "assignerShortName": "Kaspersky",
        "cveId": "CVE-2022-27535",
        "datePublished": "2022-08-05T16:47:46.000Z",
        "dateReserved": "2022-03-21T00:00:00.000Z",
        "dateUpdated": "2024-08-03T05:32:59.299Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-27534 (GCVE-0-2022-27534)

    Vulnerability from nvd – Published: 2022-04-01 22:17 – Updated: 2024-08-03 05:32
    VLAI
    Summary
    Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security with antivirus databases released before 12 March 2022 had a bug in a data parsing module that potentially allowed an attacker to execute arbitrary code. The fix was delivered automatically. Credits: Georgy Zaytsev (Positive Technologies).
    Severity
    No CVSS data available.
    CWE
    • Arbitrary Code Execution
    References
    Impacted products
    Vendor Product Version
    n/a Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security Affected: with antivirus databases released before 12.03.2022
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T05:32:59.959Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#310322_2"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "with antivirus databases released before 12.03.2022"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security with antivirus databases released before 12 March 2022 had a bug in a data parsing module that potentially allowed an attacker to execute arbitrary code. The fix was delivered automatically. Credits: Georgy Zaytsev (Positive Technologies)."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Arbitrary Code Execution",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-04-01T22:17:49.000Z",
            "orgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
            "shortName": "Kaspersky"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#310322_2"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vulnerability@kaspersky.com",
              "ID": "CVE-2022-27534",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "with antivirus databases released before 12.03.2022"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security with antivirus databases released before 12 March 2022 had a bug in a data parsing module that potentially allowed an attacker to execute arbitrary code. The fix was delivered automatically. Credits: Georgy Zaytsev (Positive Technologies)."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Arbitrary Code Execution"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#310322_2",
                  "refsource": "MISC",
                  "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#310322_2"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
        "assignerShortName": "Kaspersky",
        "cveId": "CVE-2022-27534",
        "datePublished": "2022-04-01T22:17:49.000Z",
        "dateReserved": "2022-03-21T00:00:00.000Z",
        "dateUpdated": "2024-08-03T05:32:59.959Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2021-27223 (GCVE-0-2021-27223)

    Vulnerability from nvd – Published: 2022-04-01 22:17 – Updated: 2024-08-03 20:40
    VLAI
    Summary
    A denial-of-service issue existed in one of modules that was incorporated in Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security. A local user could cause Windows crash by running a specially crafted binary module. The fix was delivered automatically. Credits: (Straghkov Denis, Kurmangaleev Shamil, Fedotov Andrey, Kuts Daniil, Mishechkin Maxim, Akolzin Vitaliy) @ ISPRAS
    Severity
    No CVSS data available.
    CWE
    • Denial-of-Service (DoS)
    References
    Impacted products
    Vendor Product Version
    n/a Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security Affected: with antivirus databases released before June 2021
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T20:40:47.509Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#310322_1"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "with antivirus databases released before June 2021"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A denial-of-service issue existed in one of modules that was incorporated in Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security. A local user could cause Windows crash by running a specially crafted binary module. The fix was delivered automatically. Credits: (Straghkov Denis, Kurmangaleev Shamil, Fedotov Andrey, Kuts Daniil, Mishechkin Maxim, Akolzin Vitaliy) @ ISPRAS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Denial-of-Service (DoS)",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-04-01T22:17:48.000Z",
            "orgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
            "shortName": "Kaspersky"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#310322_1"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vulnerability@kaspersky.com",
              "ID": "CVE-2021-27223",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "with antivirus databases released before June 2021"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A denial-of-service issue existed in one of modules that was incorporated in Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security. A local user could cause Windows crash by running a specially crafted binary module. The fix was delivered automatically. Credits: (Straghkov Denis, Kurmangaleev Shamil, Fedotov Andrey, Kuts Daniil, Mishechkin Maxim, Akolzin Vitaliy) @ ISPRAS"
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Denial-of-Service (DoS)"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#310322_1",
                  "refsource": "MISC",
                  "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#310322_1"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
        "assignerShortName": "Kaspersky",
        "cveId": "CVE-2021-27223",
        "datePublished": "2022-04-01T22:17:48.000Z",
        "dateReserved": "2021-02-15T00:00:00.000Z",
        "dateUpdated": "2024-08-03T20:40:47.509Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2021-35052 (GCVE-0-2021-35052)

    Vulnerability from nvd – Published: 2021-11-23 15:30 – Updated: 2024-08-04 00:33
    VLAI
    Summary
    A component in Kaspersky Password Manager could allow an attacker to elevate a process Integrity level from Medium to High.
    Severity
    No CVSS data available.
    CWE
    • LPE
    References
    Impacted products
    Vendor Product Version
    n/a Kaspersky Password Manager for Windows Affected: KPM for Windows prior to 9.0.2 Patch R
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T00:33:50.733Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#221121"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1335/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Kaspersky Password Manager for Windows",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "KPM for Windows prior to 9.0.2 Patch R"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A component in Kaspersky Password Manager could allow an attacker to elevate a process Integrity level from Medium to High."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "LPE",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2021-11-29T10:06:04.000Z",
            "orgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
            "shortName": "Kaspersky"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#221121"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1335/"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vulnerability@kaspersky.com",
              "ID": "CVE-2021-35052",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Kaspersky Password Manager for Windows",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "KPM for Windows prior to 9.0.2 Patch R"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A component in Kaspersky Password Manager could allow an attacker to elevate a process Integrity level from Medium to High."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "LPE"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#221121",
                  "refsource": "MISC",
                  "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#221121"
                },
                {
                  "name": "https://www.zerodayinitiative.com/advisories/ZDI-21-1335/",
                  "refsource": "MISC",
                  "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1335/"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
        "assignerShortName": "Kaspersky",
        "cveId": "CVE-2021-35052",
        "datePublished": "2021-11-23T15:30:38.000Z",
        "dateReserved": "2021-06-18T00:00:00.000Z",
        "dateUpdated": "2024-08-04T00:33:50.733Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2021-35053 (GCVE-0-2021-35053)

    Vulnerability from nvd – Published: 2021-11-03 19:11 – Updated: 2024-08-04 00:33
    VLAI
    Summary
    Possible system denial of service in case of arbitrary changing Firefox browser parameters. An attacker could change specific Firefox browser parameters file in a certain way and then reboot the system to make the system unbootable.
    Severity
    No CVSS data available.
    CWE
    • DoS
    Impacted products
    Vendor Product Version
    n/a Kaspersky Endpoint Security for Windows Affected: KES versions from 11.1 to 11.6 (inclusively)
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T00:33:50.745Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#01112021"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1280/"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-431/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Kaspersky Endpoint Security for Windows",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "KES versions from 11.1 to 11.6 (inclusively)"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Possible system denial of service in case of arbitrary changing Firefox browser parameters. An attacker could change specific Firefox browser parameters file in a certain way and then reboot the system to make the system unbootable."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "DoS",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-03-04T12:06:12.000Z",
            "orgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
            "shortName": "Kaspersky"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#01112021"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1280/"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-431/"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vulnerability@kaspersky.com",
              "ID": "CVE-2021-35053",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Kaspersky Endpoint Security for Windows",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "KES versions from 11.1 to 11.6 (inclusively)"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Possible system denial of service in case of arbitrary changing Firefox browser parameters. An attacker could change specific Firefox browser parameters file in a certain way and then reboot the system to make the system unbootable."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "DoS"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#01112021",
                  "refsource": "MISC",
                  "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#01112021"
                },
                {
                  "name": "https://www.zerodayinitiative.com/advisories/ZDI-21-1280/",
                  "refsource": "MISC",
                  "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1280/"
                },
                {
                  "name": "https://www.zerodayinitiative.com/advisories/ZDI-22-431/",
                  "refsource": "MISC",
                  "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-431/"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
        "assignerShortName": "Kaspersky",
        "cveId": "CVE-2021-35053",
        "datePublished": "2021-11-03T19:11:26.000Z",
        "dateReserved": "2021-06-18T00:00:00.000Z",
        "dateUpdated": "2024-08-04T00:33:50.745Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2020-27020 (GCVE-0-2020-27020)

    Vulnerability from nvd – Published: 2021-05-14 11:00 – Updated: 2024-08-04 16:03
    VLAI
    Summary
    Password generator feature in Kaspersky Password Manager was not completely cryptographically strong and potentially allowed an attacker to predict generated passwords in some cases. An attacker would need to know some additional information (for example, time of password generation).
    Severity
    No CVSS data available.
    CWE
    • Information Disclosure
    References
    Impacted products
    Vendor Product Version
    n/a Kaspersky Password Manager for Windows, Kaspersky Password Manager for Android, Kaspersky Password Manager for iOS Affected: KPM for Windows prior to 9.2 Patch F, KPM for Android prior to 9.2.14.872, KPM for iOS prior to 9.2.14.31
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T16:03:23.260Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#270421"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Kaspersky Password Manager for Windows, Kaspersky Password Manager for Android, Kaspersky Password Manager for iOS",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "KPM for Windows prior to 9.2 Patch F, KPM for Android prior to 9.2.14.872, KPM for iOS prior to 9.2.14.31"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Password generator feature in Kaspersky Password Manager was not completely cryptographically strong and potentially allowed an attacker to predict generated passwords in some cases. An attacker would need to know some additional information (for example, time of password generation)."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Information Disclosure",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2021-05-14T11:00:04.000Z",
            "orgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
            "shortName": "Kaspersky"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#270421"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vulnerability@kaspersky.com",
              "ID": "CVE-2020-27020",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Kaspersky Password Manager for Windows, Kaspersky Password Manager for Android, Kaspersky Password Manager for iOS",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "KPM for Windows prior to 9.2 Patch F, KPM for Android prior to 9.2.14.872, KPM for iOS prior to 9.2.14.31"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Password generator feature in Kaspersky Password Manager was not completely cryptographically strong and potentially allowed an attacker to predict generated passwords in some cases. An attacker would need to know some additional information (for example, time of password generation)."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Information Disclosure"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#270421",
                  "refsource": "MISC",
                  "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#270421"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
        "assignerShortName": "Kaspersky",
        "cveId": "CVE-2020-27020",
        "datePublished": "2021-05-14T11:00:04.000Z",
        "dateReserved": "2020-10-12T00:00:00.000Z",
        "dateUpdated": "2024-08-04T16:03:23.260Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2021-26718 (GCVE-0-2021-26718)

    Vulnerability from nvd – Published: 2021-04-01 18:00 – Updated: 2024-08-03 20:33
    VLAI
    Summary
    KIS for macOS in some use cases was vulnerable to AV bypass that potentially allowed an attacker to disable anti-virus protection.
    Severity
    No CVSS data available.
    CWE
    • Bypass
    References
    Impacted products
    Vendor Product Version
    n/a Kaspersky Internet Security for Mac Affected: prior to 21.1
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T20:33:41.245Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#310321"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Kaspersky Internet Security for Mac",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "prior to 21.1"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "KIS for macOS in some use cases was vulnerable to AV bypass that potentially allowed an attacker to disable anti-virus protection."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Bypass",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2021-04-01T18:00:59.000Z",
            "orgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
            "shortName": "Kaspersky"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#310321"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vulnerability@kaspersky.com",
              "ID": "CVE-2021-26718",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Kaspersky Internet Security for Mac",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "prior to 21.1"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "KIS for macOS in some use cases was vulnerable to AV bypass that potentially allowed an attacker to disable anti-virus protection."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Bypass"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#310321",
                  "refsource": "MISC",
                  "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#310321"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
        "assignerShortName": "Kaspersky",
        "cveId": "CVE-2021-26718",
        "datePublished": "2021-04-01T18:00:59.000Z",
        "dateReserved": "2021-02-05T00:00:00.000Z",
        "dateUpdated": "2024-08-03T20:33:41.245Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2020-26200 (GCVE-0-2020-26200)

    Vulnerability from nvd – Published: 2021-02-26 13:30 – Updated: 2024-08-04 15:49
    VLAI
    Summary
    A component of Kaspersky custom boot loader allowed loading of untrusted UEFI modules due to insufficient check of their authenticity. This component is incorporated in Kaspersky Rescue Disk (KRD) and was trusted by the Authentication Agent of Full Disk Encryption in Kaspersky Endpoint Security (KES). This issue allowed to bypass the UEFI Secure Boot security feature. An attacker would need physical access to the computer to exploit it. Otherwise, local administrator privileges would be required to modify the boot loader component.
    Severity
    No CVSS data available.
    CWE
    • Bypass
    References
    Impacted products
    Vendor Product Version
    N/A Kaspersky Rescue Disk Version Affected: All versions prior to 18.0.11.3 (patch C)
    Create a notification for this product.
    N/A Kaspersky Endpoint Security with the Full Disk Encryption component installed Affected: 10 SP2 MR2
    Affected: 10 SP2 MR3
    Affected: 11.0.0
    Affected: 11.0.1
    Affected: 11.1.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T15:49:07.172Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#170221"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Kaspersky Rescue Disk Version",
              "vendor": "N/A",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions prior to 18.0.11.3 (patch C)"
                }
              ]
            },
            {
              "product": "Kaspersky Endpoint Security with the Full Disk Encryption component installed",
              "vendor": "N/A",
              "versions": [
                {
                  "status": "affected",
                  "version": "10 SP2 MR2"
                },
                {
                  "status": "affected",
                  "version": "10 SP2 MR3"
                },
                {
                  "status": "affected",
                  "version": "11.0.0"
                },
                {
                  "status": "affected",
                  "version": "11.0.1"
                },
                {
                  "status": "affected",
                  "version": "11.1.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A component of Kaspersky custom boot loader allowed loading of untrusted UEFI modules due to insufficient check of their authenticity. This component is incorporated in Kaspersky Rescue Disk (KRD) and was trusted by the Authentication Agent of Full Disk Encryption in Kaspersky Endpoint Security (KES). This issue allowed to bypass the UEFI Secure Boot security feature. An attacker would need physical access to the computer to exploit it. Otherwise, local administrator privileges would be required to modify the boot loader component."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Bypass",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2021-02-26T13:30:23.000Z",
            "orgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
            "shortName": "Kaspersky"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#170221"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vulnerability@kaspersky.com",
              "ID": "CVE-2020-26200",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Kaspersky Rescue Disk Version",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "All versions prior to 18.0.11.3 (patch C)"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Kaspersky Endpoint Security with the Full Disk Encryption component installed",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "10 SP2 MR2"
                              },
                              {
                                "version_value": "10 SP2 MR3"
                              },
                              {
                                "version_value": "11.0.0"
                              },
                              {
                                "version_value": "11.0.1"
                              },
                              {
                                "version_value": "11.1.0"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "N/A"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A component of Kaspersky custom boot loader allowed loading of untrusted UEFI modules due to insufficient check of their authenticity. This component is incorporated in Kaspersky Rescue Disk (KRD) and was trusted by the Authentication Agent of Full Disk Encryption in Kaspersky Endpoint Security (KES). This issue allowed to bypass the UEFI Secure Boot security feature. An attacker would need physical access to the computer to exploit it. Otherwise, local administrator privileges would be required to modify the boot loader component."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Bypass"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#170221",
                  "refsource": "MISC",
                  "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#170221"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
        "assignerShortName": "Kaspersky",
        "cveId": "CVE-2020-26200",
        "datePublished": "2021-02-26T13:30:23.000Z",
        "dateReserved": "2020-09-30T00:00:00.000Z",
        "dateUpdated": "2024-08-04T15:49:07.172Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2020-36200 (GCVE-0-2020-36200)

    Vulnerability from nvd – Published: 2021-01-21 21:23 – Updated: 2024-08-04 17:23
    VLAI
    Summary
    TinyCheck before commits 9fd360d and ea53de8 allowed an authenticated attacker to send an HTTP GET request to the crafted URLs.
    Severity
    No CVSS data available.
    CWE
    • Server-Side Request Forgery (SSRF)
    References
    Impacted products
    Vendor Product Version
    n/a Kaspersky TinyCheck Affected: without commits 9fd360d and ea53de8
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T17:23:09.508Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://github.com/KasperskyLab/TinyCheck/security/advisories/GHSA-gqpw-3669-6w5h"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Kaspersky TinyCheck",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "without commits 9fd360d and ea53de8"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "TinyCheck before commits 9fd360d and ea53de8 allowed an authenticated attacker to send an HTTP GET request to the crafted URLs."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Server-Side Request Forgery (SSRF)",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2021-01-21T21:23:00.000Z",
            "orgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
            "shortName": "Kaspersky"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/KasperskyLab/TinyCheck/security/advisories/GHSA-gqpw-3669-6w5h"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vulnerability@kaspersky.com",
              "ID": "CVE-2020-36200",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Kaspersky TinyCheck",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "without commits 9fd360d and ea53de8"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "TinyCheck before commits 9fd360d and ea53de8 allowed an authenticated attacker to send an HTTP GET request to the crafted URLs."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Server-Side Request Forgery (SSRF)"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://github.com/KasperskyLab/TinyCheck/security/advisories/GHSA-gqpw-3669-6w5h",
                  "refsource": "MISC",
                  "url": "https://github.com/KasperskyLab/TinyCheck/security/advisories/GHSA-gqpw-3669-6w5h"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
        "assignerShortName": "Kaspersky",
        "cveId": "CVE-2020-36200",
        "datePublished": "2021-01-21T21:23:00.000Z",
        "dateReserved": "2021-01-20T00:00:00.000Z",
        "dateUpdated": "2024-08-04T17:23:09.508Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2025-64984 (GCVE-0-2025-64984)

    Vulnerability from cvelistv5 – Published: 2025-11-20 06:53 – Updated: 2025-11-20 15:42
    VLAI
    Summary
    Kaspersky has fixed a security issue in Kaspersky Endpoint Security for Linux (any version with anti-virus databases prior to 18.11.2025), Kaspersky Industrial CyberSecurity for Linux Nodes (any version with anti-virus databases prior to 18.11.2025), and Kaspersky Endpoint Security for Mac (12.0.0.325, 12.1.0.553, and 12.2.0.694 with anti-virus databases prior to 18.11.2025) that could have allowed a reflected XSS attack to be carried out by an attacker using phishing techniques.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-11-20 15:42 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    References
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-64984",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-11-20T15:42:09.290134Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-11-20T15:42:14.162Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "MacOS"
              ],
              "product": "Kaspersky Endpoint Security",
              "vendor": "Kaspersky",
              "versions": [
                {
                  "status": "affected",
                  "version": "12.0.0.325"
                },
                {
                  "status": "affected",
                  "version": "12.1.0.553"
                },
                {
                  "status": "unknown",
                  "version": "12.2.0.694"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "platforms": [
                "Linux"
              ],
              "product": "Kaspersky Endpoint Security",
              "vendor": "Kaspersky"
            },
            {
              "defaultStatus": "unknown",
              "platforms": [
                "Linux"
              ],
              "product": "Kaspersky Industrial CyberSecurity for Linux Nodes",
              "vendor": "Kaspersky"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Kaspersky has fixed a security issue in Kaspersky Endpoint Security for Linux (any version with anti-virus databases prior to 18.11.2025), Kaspersky Industrial CyberSecurity for Linux Nodes (any version with anti-virus databases prior to 18.11.2025), and Kaspersky Endpoint Security for Mac (12.0.0.325, 12.1.0.553, and 12.2.0.694 with anti-virus databases prior to 18.11.2025) that could have allowed a reflected XSS attack to be carried out by an attacker using phishing techniques."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.1,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                "version": "3.1"
              },
              "cvssV4_0": {
                "baseScore": 5.1,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
                "version": "4.0"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79: Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-11-20T06:53:39.628Z",
            "orgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
            "shortName": "Kaspersky"
          },
          "references": [
            {
              "name": "Advisory issued on November 18, 2025",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://support.kaspersky.com/vulnerability/list-of-advisories/12430#181125"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Users should update anti-virus databases to use at least the version from 11/18/2025."
            },
            {
              "lang": "en",
              "value": "Users of Kaspersky Endpoint Security for Mac versions 12.0.0.325 and 12.1.0.553 are recommended to update the application to version 12.2.0.694 with the latest version of the anti-virus databases."
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2025-11-18T00:00:00.000Z",
              "value": "Advisory published by Kaspersky"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
        "assignerShortName": "Kaspersky",
        "cveId": "CVE-2025-64984",
        "datePublished": "2025-11-20T06:53:39.628Z",
        "dateReserved": "2025-11-12T07:42:11.731Z",
        "dateUpdated": "2025-11-20T15:42:14.162Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-13614 (GCVE-0-2024-13614)

    Vulnerability from cvelistv5 – Published: 2025-02-06 16:13 – Updated: 2025-02-12 19:51
    VLAI
    Summary
    Kaspersky has fixed a security issue in Kaspersky Anti-Virus SDK for Windows, Kaspersky Security for Virtualization Light Agent, Kaspersky Endpoint Security for Windows, Kaspersky Small Office Security, Kaspersky for Windows (Standard, Plus, Premium), Kaspersky Free, Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Security Cloud, Kaspersky Safe Kids, Kaspersky Anti-Ransomware Tool that could allow an authenticated attacker to write data to a limited area outside the allocated kernel memory buffer. The fix was installed automatically for all Kaspersky Endpoint products.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-02-06 16:34 UTC
    CWE
    • CWE-190 - Integer Overflow or Wraparound
    References
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-13614",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-02-06T16:34:12.660585Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-02-12T19:51:09.532Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Kaspersky Anti-Virus SDK for Windows",
              "vendor": "Kaspersky",
              "versions": [
                {
                  "lessThanOrEqual": "8.10.1.1943",
                  "status": "affected",
                  "version": "8.10.1.1943",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "8.10.1.1943 CF",
                  "status": "affected",
                  "version": "8.10.1.1943 CF",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Kaspersky Security for Virtualization Light Agent",
              "vendor": "Kaspersky",
              "versions": [
                {
                  "lessThan": "5.2.27.319",
                  "status": "affected",
                  "version": "5.2",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "5.2.27.319",
                  "status": "unknown",
                  "version": "5.2.27.319",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Kaspersky Endpoint Security for Windows",
              "vendor": "Kaspersky"
            },
            {
              "defaultStatus": "unknown",
              "product": "Kaspersky Small Office Security",
              "vendor": "Kaspersky"
            },
            {
              "defaultStatus": "unknown",
              "product": "Kaspersky for Windows (Standard, Plus, Premium)",
              "vendor": "Kaspersky"
            },
            {
              "defaultStatus": "unknown",
              "product": "Kaspersky Free",
              "vendor": "Kaspersky"
            },
            {
              "defaultStatus": "unknown",
              "product": "Kaspersky Anti-Virus",
              "vendor": "Kaspersky"
            },
            {
              "defaultStatus": "unknown",
              "product": "Kaspersky Internet Security",
              "vendor": "Kaspersky"
            },
            {
              "defaultStatus": "unknown",
              "product": "Kaspersky Security Cloud",
              "vendor": "Kaspersky"
            },
            {
              "defaultStatus": "unknown",
              "product": "Kaspersky Safe Kids",
              "vendor": "Kaspersky"
            },
            {
              "defaultStatus": "unknown",
              "product": "Kaspersky Anti-Ransomware Tool",
              "vendor": "Kaspersky"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Florian Schweins"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Kaspersky has fixed a security issue in Kaspersky Anti-Virus SDK for Windows, Kaspersky Security for Virtualization Light Agent, Kaspersky Endpoint Security for Windows, Kaspersky Small Office Security, Kaspersky for Windows (Standard, Plus, Premium), Kaspersky Free, Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Security Cloud, Kaspersky Safe Kids, Kaspersky Anti-Ransomware Tool that could allow an authenticated attacker to write data to a limited area outside the allocated kernel memory buffer. The fix was installed automatically for all Kaspersky Endpoint products."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "value": "There have been no recorded attempts to exploit this issue in the wild."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-190",
                  "description": "CWE-190: Integer Overflow or Wraparound",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-02-06T16:16:54.229Z",
            "orgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
            "shortName": "Kaspersky"
          },
          "references": [
            {
              "name": "Advisory issued on February 6, 2025",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://support.kaspersky.com/vulnerability/list-of-advisories/12430#060225"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "To fix the vulnerability, upgrade the KAV SDK for Windows to the following version: Kaspersky Anti-Virus Software Development Kit 8 Level 3 v. 8.10.2.2098. Contact your Technical Account Manager to obtain the necessary instructions."
            },
            {
              "lang": "en",
              "value": "Install Kaspersky Security for Virtualization Light Agent 5.2.27.319 (with Kaspersky Security Components Installation Wizard 5.2.1.4005) or newer using the following url: https://www.kaspersky.com/small-to-medium-business-security/downloads/virtualization-hybrid-cloud"
            },
            {
              "lang": "en",
              "value": "The fix was installed automatically for Kaspersky Endpoint Security for Windows. To check for the fix, check the antivirus database update date, it should be November 6, 2024 or newer."
            },
            {
              "lang": "en",
              "value": "The fix was installed automatically for Kaspersky Small Office Security. To check for the fix, check the antivirus database update date, it should be November 6, 2024 or newer."
            },
            {
              "lang": "en",
              "value": "The fix was installed automatically for Kaspersky for Windows (Standard, Plus, Premium). To check for the fix, check the antivirus database update date, it should be November 6, 2024 or newer."
            },
            {
              "lang": "en",
              "value": "The fix was installed automatically for Kaspersky Free. To check for the fix, check the antivirus database update date, it should be November 6, 2024 or newer."
            },
            {
              "lang": "en",
              "value": "The fix was installed automatically for Kaspersky Anti-Virus. To check for the fix, check the antivirus database update date, it should be November 6, 2024 or newer."
            },
            {
              "lang": "en",
              "value": "The fix was installed automatically for Kaspersky Internet Security. To check for the fix, check the antivirus database update date, it should be November 6, 2024 or newer."
            },
            {
              "lang": "en",
              "value": "The fix was installed automatically for Kaspersky Security Cloud. To check for the fix, check the antivirus database update date, it should be November 6, 2024 or newer."
            },
            {
              "lang": "en",
              "value": "The fix was installed automatically for Kaspersky Safe Kids. To check for the fix, check the antivirus database update date, it should be November 6, 2024 or newer."
            },
            {
              "lang": "en",
              "value": "The fix was installed automatically for Kaspersky Anti-Ransomware Tool. To check for the fix, check the antivirus database update date, it should be November 6, 2024 or newer."
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2025-02-06T00:00:00.000Z",
              "value": "Advisory published by Kaspersky"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
        "assignerShortName": "Kaspersky",
        "cveId": "CVE-2024-13614",
        "datePublished": "2025-02-06T16:13:08.173Z",
        "dateReserved": "2025-01-22T06:31:25.425Z",
        "dateUpdated": "2025-02-12T19:51:09.532Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-23349 (GCVE-0-2023-23349)

    Vulnerability from cvelistv5 – Published: 2024-03-22 16:15 – Updated: 2025-04-10 20:10
    VLAI
    Summary
    Kaspersky has fixed a security issue in Kaspersky Password Manager (KPM) for Windows that allowed a local user to recover the auto-filled credentials from a memory dump when the KPM extension for Google Chrome is used. To exploit the issue, an attacker must trick a user into visiting a login form of a website with the saved credentials, and the KPM extension must autofill these credentials. The attacker must then launch a malware module to steal those specific credentials.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-03-25 16:49 UTC
    CWE
    • CWE-316 - Cleartext Storage of Sensitive Information in Memory
    References
    Impacted products
    Vendor Product Version
    Kaspersky Kaspersky Password Manager for Windows Affected: * , < 24.0.0.427 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-23349",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-03-25T16:49:20.375552Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-10T20:10:58.369Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T10:28:40.854Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "Advisory issued on March 18, 2024",
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://support.kaspersky.com/vulnerability/list-of-advisories/12430#180324"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Kaspersky Password Manager for Windows",
              "vendor": "Kaspersky",
              "versions": [
                {
                  "lessThan": "24.0.0.427",
                  "status": "affected",
                  "version": "*",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Efstratios Chatzoglou"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Zisis Tsiatsikas"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Vyron Kampourakis"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Kaspersky has fixed a security issue in Kaspersky Password Manager (KPM) for Windows that allowed a local user to recover the auto-filled credentials from a memory dump when the KPM extension for Google Chrome is used. To exploit the issue, an attacker must trick a user into visiting a login form of a website with the saved credentials, and the KPM extension must autofill these credentials. The attacker must then launch a malware module to steal those specific credentials."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "LOCAL",
                "availabilityImpact": "NONE",
                "baseScore": 2.2,
                "baseSeverity": "LOW",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-316",
                  "description": "CWE-316: Cleartext Storage of Sensitive Information in Memory",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-03-27T11:51:13.706Z",
            "orgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
            "shortName": "Kaspersky"
          },
          "references": [
            {
              "name": "Advisory issued on March 18, 2024",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://support.kaspersky.com/vulnerability/list-of-advisories/12430#180324"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Install Kaspersky Password Manager (KPM) version 24.0.0.427 or later using the following url: https://support.kaspersky.com/help/KPM/Win24.0/en-US/85241.htm"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2024-03-18T00:00:00.000Z",
              "value": "Advisory published by Kaspersky"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
        "assignerShortName": "Kaspersky",
        "cveId": "CVE-2023-23349",
        "datePublished": "2024-03-22T16:15:55.200Z",
        "dateReserved": "2023-01-11T20:11:14.512Z",
        "dateUpdated": "2025-04-10T20:10:58.369Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-1619 (GCVE-0-2024-1619)

    Vulnerability from cvelistv5 – Published: 2024-02-29 09:22 – Updated: 2024-08-01 18:48
    VLAI
    Summary
    Kaspersky has fixed a security issue in the Kaspersky Security 8.0 for Linux Mail Server. The issue was that an attacker could potentially force an administrator to click on a malicious link to perform unauthorized actions.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-03-11 16:14 UTC
    CWE
    • CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
    References
    Impacted products
    Vendor Product Version
    Kaspersky Kaspersky Security for Linux Mail Server 8 Affected: * , < 8.0.3.30 Security Patch A (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-1619",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-03-11T16:14:26.090266Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-04T18:00:28.058Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T18:48:20.684Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "Advisory issued on February 1, 2024",
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://support.kaspersky.com/vulnerability/list-of-advisories/12430#010224"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Kaspersky Security for Linux Mail Server 8",
              "vendor": "Kaspersky",
              "versions": [
                {
                  "lessThan": "8.0.3.30 Security Patch A",
                  "status": "affected",
                  "version": "*",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Adrian Tiron"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Bogdan Tiron"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Kaspersky has fixed a security issue in the Kaspersky Security 8.0 for Linux Mail Server. The issue was that an attacker could potentially force an administrator to click on a malicious link to perform unauthorized actions."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.1,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-74",
                  "description": "CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component (\u0027Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-02-29T09:22:03.588Z",
            "orgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
            "shortName": "Kaspersky"
          },
          "references": [
            {
              "name": "Advisory issued on February 1, 2024",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://support.kaspersky.com/vulnerability/list-of-advisories/12430#010224"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Install version 8.0.3.30 Security Patch A of Kaspersky Security 8.0 for Linux Mail Server."
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2024-02-01T00:00:00.000Z",
              "value": "Advisory published by Kaspersky"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
        "assignerShortName": "Kaspersky",
        "cveId": "CVE-2024-1619",
        "datePublished": "2024-02-29T09:22:03.588Z",
        "dateReserved": "2024-02-19T08:38:14.449Z",
        "dateUpdated": "2024-08-01T18:48:20.684Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-27535 (GCVE-0-2022-27535)

    Vulnerability from cvelistv5 – Published: 2022-08-05 16:47 – Updated: 2024-08-03 05:32
    VLAI
    Summary
    Kaspersky VPN Secure Connection for Windows version up to 21.5 was vulnerable to arbitrary file deletion via abuse of its 'Delete All Service Data And Reports' feature by the local authenticated attacker.
    Severity
    No CVSS data available.
    CWE
    • Local Privilege Escalation (LPE)
    Impacted products
    Vendor Product Version
    n/a Kaspersky VPN Secure Connection for Windows Affected: prior to 21.6
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T05:32:59.299Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#050822"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.synopsys.com/blogs/software-security/cyrc-advisory-kasperksy-vpn-microsoft-windows/"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://forum.kaspersky.com/topic/kaspersky-statement-on-cve-2022-27535-26742/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Kaspersky VPN Secure Connection for Windows",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "prior to 21.6"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Kaspersky VPN Secure Connection for Windows version up to 21.5 was vulnerable to arbitrary file deletion via abuse of its \u0027Delete All Service Data And Reports\u0027 feature by the local authenticated attacker."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Local Privilege Escalation (LPE)",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-08-09T19:55:41.000Z",
            "orgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
            "shortName": "Kaspersky"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#050822"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.synopsys.com/blogs/software-security/cyrc-advisory-kasperksy-vpn-microsoft-windows/"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://forum.kaspersky.com/topic/kaspersky-statement-on-cve-2022-27535-26742/"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vulnerability@kaspersky.com",
              "ID": "CVE-2022-27535",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Kaspersky VPN Secure Connection for Windows",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "prior to 21.6"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Kaspersky VPN Secure Connection for Windows version up to 21.5 was vulnerable to arbitrary file deletion via abuse of its \u0027Delete All Service Data And Reports\u0027 feature by the local authenticated attacker."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Local Privilege Escalation (LPE)"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#050822",
                  "refsource": "MISC",
                  "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#050822"
                },
                {
                  "name": "https://www.synopsys.com/blogs/software-security/cyrc-advisory-kasperksy-vpn-microsoft-windows/",
                  "refsource": "MISC",
                  "url": "https://www.synopsys.com/blogs/software-security/cyrc-advisory-kasperksy-vpn-microsoft-windows/"
                },
                {
                  "name": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#050822",
                  "refsource": "MISC",
                  "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#050822"
                },
                {
                  "name": "https://forum.kaspersky.com/topic/kaspersky-statement-on-cve-2022-27535-26742/",
                  "refsource": "MISC",
                  "url": "https://forum.kaspersky.com/topic/kaspersky-statement-on-cve-2022-27535-26742/"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
        "assignerShortName": "Kaspersky",
        "cveId": "CVE-2022-27535",
        "datePublished": "2022-08-05T16:47:46.000Z",
        "dateReserved": "2022-03-21T00:00:00.000Z",
        "dateUpdated": "2024-08-03T05:32:59.299Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-27534 (GCVE-0-2022-27534)

    Vulnerability from cvelistv5 – Published: 2022-04-01 22:17 – Updated: 2024-08-03 05:32
    VLAI
    Summary
    Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security with antivirus databases released before 12 March 2022 had a bug in a data parsing module that potentially allowed an attacker to execute arbitrary code. The fix was delivered automatically. Credits: Georgy Zaytsev (Positive Technologies).
    Severity
    No CVSS data available.
    CWE
    • Arbitrary Code Execution
    References
    Impacted products
    Vendor Product Version
    n/a Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security Affected: with antivirus databases released before 12.03.2022
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T05:32:59.959Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#310322_2"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "with antivirus databases released before 12.03.2022"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security with antivirus databases released before 12 March 2022 had a bug in a data parsing module that potentially allowed an attacker to execute arbitrary code. The fix was delivered automatically. Credits: Georgy Zaytsev (Positive Technologies)."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Arbitrary Code Execution",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-04-01T22:17:49.000Z",
            "orgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
            "shortName": "Kaspersky"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#310322_2"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vulnerability@kaspersky.com",
              "ID": "CVE-2022-27534",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "with antivirus databases released before 12.03.2022"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security with antivirus databases released before 12 March 2022 had a bug in a data parsing module that potentially allowed an attacker to execute arbitrary code. The fix was delivered automatically. Credits: Georgy Zaytsev (Positive Technologies)."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Arbitrary Code Execution"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#310322_2",
                  "refsource": "MISC",
                  "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#310322_2"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
        "assignerShortName": "Kaspersky",
        "cveId": "CVE-2022-27534",
        "datePublished": "2022-04-01T22:17:49.000Z",
        "dateReserved": "2022-03-21T00:00:00.000Z",
        "dateUpdated": "2024-08-03T05:32:59.959Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2021-27223 (GCVE-0-2021-27223)

    Vulnerability from cvelistv5 – Published: 2022-04-01 22:17 – Updated: 2024-08-03 20:40
    VLAI
    Summary
    A denial-of-service issue existed in one of modules that was incorporated in Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security. A local user could cause Windows crash by running a specially crafted binary module. The fix was delivered automatically. Credits: (Straghkov Denis, Kurmangaleev Shamil, Fedotov Andrey, Kuts Daniil, Mishechkin Maxim, Akolzin Vitaliy) @ ISPRAS
    Severity
    No CVSS data available.
    CWE
    • Denial-of-Service (DoS)
    References
    Impacted products
    Vendor Product Version
    n/a Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security Affected: with antivirus databases released before June 2021
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T20:40:47.509Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#310322_1"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "with antivirus databases released before June 2021"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A denial-of-service issue existed in one of modules that was incorporated in Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security. A local user could cause Windows crash by running a specially crafted binary module. The fix was delivered automatically. Credits: (Straghkov Denis, Kurmangaleev Shamil, Fedotov Andrey, Kuts Daniil, Mishechkin Maxim, Akolzin Vitaliy) @ ISPRAS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Denial-of-Service (DoS)",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-04-01T22:17:48.000Z",
            "orgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
            "shortName": "Kaspersky"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#310322_1"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vulnerability@kaspersky.com",
              "ID": "CVE-2021-27223",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "with antivirus databases released before June 2021"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A denial-of-service issue existed in one of modules that was incorporated in Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security. A local user could cause Windows crash by running a specially crafted binary module. The fix was delivered automatically. Credits: (Straghkov Denis, Kurmangaleev Shamil, Fedotov Andrey, Kuts Daniil, Mishechkin Maxim, Akolzin Vitaliy) @ ISPRAS"
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Denial-of-Service (DoS)"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#310322_1",
                  "refsource": "MISC",
                  "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#310322_1"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
        "assignerShortName": "Kaspersky",
        "cveId": "CVE-2021-27223",
        "datePublished": "2022-04-01T22:17:48.000Z",
        "dateReserved": "2021-02-15T00:00:00.000Z",
        "dateUpdated": "2024-08-03T20:40:47.509Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2021-35052 (GCVE-0-2021-35052)

    Vulnerability from cvelistv5 – Published: 2021-11-23 15:30 – Updated: 2024-08-04 00:33
    VLAI
    Summary
    A component in Kaspersky Password Manager could allow an attacker to elevate a process Integrity level from Medium to High.
    Severity
    No CVSS data available.
    CWE
    • LPE
    References
    Impacted products
    Vendor Product Version
    n/a Kaspersky Password Manager for Windows Affected: KPM for Windows prior to 9.0.2 Patch R
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T00:33:50.733Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#221121"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1335/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Kaspersky Password Manager for Windows",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "KPM for Windows prior to 9.0.2 Patch R"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A component in Kaspersky Password Manager could allow an attacker to elevate a process Integrity level from Medium to High."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "LPE",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2021-11-29T10:06:04.000Z",
            "orgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
            "shortName": "Kaspersky"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#221121"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1335/"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vulnerability@kaspersky.com",
              "ID": "CVE-2021-35052",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Kaspersky Password Manager for Windows",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "KPM for Windows prior to 9.0.2 Patch R"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A component in Kaspersky Password Manager could allow an attacker to elevate a process Integrity level from Medium to High."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "LPE"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#221121",
                  "refsource": "MISC",
                  "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#221121"
                },
                {
                  "name": "https://www.zerodayinitiative.com/advisories/ZDI-21-1335/",
                  "refsource": "MISC",
                  "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1335/"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
        "assignerShortName": "Kaspersky",
        "cveId": "CVE-2021-35052",
        "datePublished": "2021-11-23T15:30:38.000Z",
        "dateReserved": "2021-06-18T00:00:00.000Z",
        "dateUpdated": "2024-08-04T00:33:50.733Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2021-35053 (GCVE-0-2021-35053)

    Vulnerability from cvelistv5 – Published: 2021-11-03 19:11 – Updated: 2024-08-04 00:33
    VLAI
    Summary
    Possible system denial of service in case of arbitrary changing Firefox browser parameters. An attacker could change specific Firefox browser parameters file in a certain way and then reboot the system to make the system unbootable.
    Severity
    No CVSS data available.
    CWE
    • DoS
    Impacted products
    Vendor Product Version
    n/a Kaspersky Endpoint Security for Windows Affected: KES versions from 11.1 to 11.6 (inclusively)
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T00:33:50.745Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#01112021"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1280/"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-431/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Kaspersky Endpoint Security for Windows",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "KES versions from 11.1 to 11.6 (inclusively)"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Possible system denial of service in case of arbitrary changing Firefox browser parameters. An attacker could change specific Firefox browser parameters file in a certain way and then reboot the system to make the system unbootable."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "DoS",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-03-04T12:06:12.000Z",
            "orgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
            "shortName": "Kaspersky"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#01112021"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1280/"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-431/"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vulnerability@kaspersky.com",
              "ID": "CVE-2021-35053",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Kaspersky Endpoint Security for Windows",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "KES versions from 11.1 to 11.6 (inclusively)"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Possible system denial of service in case of arbitrary changing Firefox browser parameters. An attacker could change specific Firefox browser parameters file in a certain way and then reboot the system to make the system unbootable."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "DoS"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#01112021",
                  "refsource": "MISC",
                  "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#01112021"
                },
                {
                  "name": "https://www.zerodayinitiative.com/advisories/ZDI-21-1280/",
                  "refsource": "MISC",
                  "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1280/"
                },
                {
                  "name": "https://www.zerodayinitiative.com/advisories/ZDI-22-431/",
                  "refsource": "MISC",
                  "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-431/"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
        "assignerShortName": "Kaspersky",
        "cveId": "CVE-2021-35053",
        "datePublished": "2021-11-03T19:11:26.000Z",
        "dateReserved": "2021-06-18T00:00:00.000Z",
        "dateUpdated": "2024-08-04T00:33:50.745Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2020-27020 (GCVE-0-2020-27020)

    Vulnerability from cvelistv5 – Published: 2021-05-14 11:00 – Updated: 2024-08-04 16:03
    VLAI
    Summary
    Password generator feature in Kaspersky Password Manager was not completely cryptographically strong and potentially allowed an attacker to predict generated passwords in some cases. An attacker would need to know some additional information (for example, time of password generation).
    Severity
    No CVSS data available.
    CWE
    • Information Disclosure
    References
    Impacted products
    Vendor Product Version
    n/a Kaspersky Password Manager for Windows, Kaspersky Password Manager for Android, Kaspersky Password Manager for iOS Affected: KPM for Windows prior to 9.2 Patch F, KPM for Android prior to 9.2.14.872, KPM for iOS prior to 9.2.14.31
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T16:03:23.260Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#270421"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Kaspersky Password Manager for Windows, Kaspersky Password Manager for Android, Kaspersky Password Manager for iOS",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "KPM for Windows prior to 9.2 Patch F, KPM for Android prior to 9.2.14.872, KPM for iOS prior to 9.2.14.31"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Password generator feature in Kaspersky Password Manager was not completely cryptographically strong and potentially allowed an attacker to predict generated passwords in some cases. An attacker would need to know some additional information (for example, time of password generation)."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Information Disclosure",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2021-05-14T11:00:04.000Z",
            "orgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
            "shortName": "Kaspersky"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#270421"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vulnerability@kaspersky.com",
              "ID": "CVE-2020-27020",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Kaspersky Password Manager for Windows, Kaspersky Password Manager for Android, Kaspersky Password Manager for iOS",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "KPM for Windows prior to 9.2 Patch F, KPM for Android prior to 9.2.14.872, KPM for iOS prior to 9.2.14.31"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Password generator feature in Kaspersky Password Manager was not completely cryptographically strong and potentially allowed an attacker to predict generated passwords in some cases. An attacker would need to know some additional information (for example, time of password generation)."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Information Disclosure"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#270421",
                  "refsource": "MISC",
                  "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#270421"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
        "assignerShortName": "Kaspersky",
        "cveId": "CVE-2020-27020",
        "datePublished": "2021-05-14T11:00:04.000Z",
        "dateReserved": "2020-10-12T00:00:00.000Z",
        "dateUpdated": "2024-08-04T16:03:23.260Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2021-26718 (GCVE-0-2021-26718)

    Vulnerability from cvelistv5 – Published: 2021-04-01 18:00 – Updated: 2024-08-03 20:33
    VLAI
    Summary
    KIS for macOS in some use cases was vulnerable to AV bypass that potentially allowed an attacker to disable anti-virus protection.
    Severity
    No CVSS data available.
    CWE
    • Bypass
    References
    Impacted products
    Vendor Product Version
    n/a Kaspersky Internet Security for Mac Affected: prior to 21.1
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T20:33:41.245Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#310321"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Kaspersky Internet Security for Mac",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "prior to 21.1"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "KIS for macOS in some use cases was vulnerable to AV bypass that potentially allowed an attacker to disable anti-virus protection."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Bypass",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2021-04-01T18:00:59.000Z",
            "orgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
            "shortName": "Kaspersky"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#310321"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vulnerability@kaspersky.com",
              "ID": "CVE-2021-26718",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Kaspersky Internet Security for Mac",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "prior to 21.1"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "KIS for macOS in some use cases was vulnerable to AV bypass that potentially allowed an attacker to disable anti-virus protection."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Bypass"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#310321",
                  "refsource": "MISC",
                  "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#310321"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
        "assignerShortName": "Kaspersky",
        "cveId": "CVE-2021-26718",
        "datePublished": "2021-04-01T18:00:59.000Z",
        "dateReserved": "2021-02-05T00:00:00.000Z",
        "dateUpdated": "2024-08-03T20:33:41.245Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2020-26200 (GCVE-0-2020-26200)

    Vulnerability from cvelistv5 – Published: 2021-02-26 13:30 – Updated: 2024-08-04 15:49
    VLAI
    Summary
    A component of Kaspersky custom boot loader allowed loading of untrusted UEFI modules due to insufficient check of their authenticity. This component is incorporated in Kaspersky Rescue Disk (KRD) and was trusted by the Authentication Agent of Full Disk Encryption in Kaspersky Endpoint Security (KES). This issue allowed to bypass the UEFI Secure Boot security feature. An attacker would need physical access to the computer to exploit it. Otherwise, local administrator privileges would be required to modify the boot loader component.
    Severity
    No CVSS data available.
    CWE
    • Bypass
    References
    Impacted products
    Vendor Product Version
    N/A Kaspersky Rescue Disk Version Affected: All versions prior to 18.0.11.3 (patch C)
    Create a notification for this product.
    N/A Kaspersky Endpoint Security with the Full Disk Encryption component installed Affected: 10 SP2 MR2
    Affected: 10 SP2 MR3
    Affected: 11.0.0
    Affected: 11.0.1
    Affected: 11.1.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T15:49:07.172Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#170221"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Kaspersky Rescue Disk Version",
              "vendor": "N/A",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions prior to 18.0.11.3 (patch C)"
                }
              ]
            },
            {
              "product": "Kaspersky Endpoint Security with the Full Disk Encryption component installed",
              "vendor": "N/A",
              "versions": [
                {
                  "status": "affected",
                  "version": "10 SP2 MR2"
                },
                {
                  "status": "affected",
                  "version": "10 SP2 MR3"
                },
                {
                  "status": "affected",
                  "version": "11.0.0"
                },
                {
                  "status": "affected",
                  "version": "11.0.1"
                },
                {
                  "status": "affected",
                  "version": "11.1.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A component of Kaspersky custom boot loader allowed loading of untrusted UEFI modules due to insufficient check of their authenticity. This component is incorporated in Kaspersky Rescue Disk (KRD) and was trusted by the Authentication Agent of Full Disk Encryption in Kaspersky Endpoint Security (KES). This issue allowed to bypass the UEFI Secure Boot security feature. An attacker would need physical access to the computer to exploit it. Otherwise, local administrator privileges would be required to modify the boot loader component."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Bypass",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2021-02-26T13:30:23.000Z",
            "orgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
            "shortName": "Kaspersky"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#170221"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "vulnerability@kaspersky.com",
              "ID": "CVE-2020-26200",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Kaspersky Rescue Disk Version",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "All versions prior to 18.0.11.3 (patch C)"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Kaspersky Endpoint Security with the Full Disk Encryption component installed",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "10 SP2 MR2"
                              },
                              {
                                "version_value": "10 SP2 MR3"
                              },
                              {
                                "version_value": "11.0.0"
                              },
                              {
                                "version_value": "11.0.1"
                              },
                              {
                                "version_value": "11.1.0"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "N/A"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A component of Kaspersky custom boot loader allowed loading of untrusted UEFI modules due to insufficient check of their authenticity. This component is incorporated in Kaspersky Rescue Disk (KRD) and was trusted by the Authentication Agent of Full Disk Encryption in Kaspersky Endpoint Security (KES). This issue allowed to bypass the UEFI Secure Boot security feature. An attacker would need physical access to the computer to exploit it. Otherwise, local administrator privileges would be required to modify the boot loader component."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Bypass"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#170221",
                  "refsource": "MISC",
                  "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#170221"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988",
        "assignerShortName": "Kaspersky",
        "cveId": "CVE-2020-26200",
        "datePublished": "2021-02-26T13:30:23.000Z",
        "dateReserved": "2020-09-30T00:00:00.000Z",
        "dateUpdated": "2024-08-04T15:49:07.172Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }