Weak Permissions in Kaspersky Internet Security for Android
CVE-2017-12816
9.8CRITICAL
Key Information:
- Vendor
- Kaspersky
- Vendor
- CVE Published:
- 25 August 2017
Summary
In Kaspersky Internet Security for Android version 11.12.4.1622, certain exported activities have insufficient permission settings. This weakness allows potentially harmful applications to gain unauthorized access to the functionalities of Kaspersky’s security product via Android's Inter-Process Communication (IPC). Attackers could exploit this vulnerability to manipulate security features, putting user safety at risk.
Affected Version(s)
Kaspersky Lab Kaspersky Internet Security for Android 11.12.4.1622 Kaspersky Lab Kaspersky Internet Security for Android 11.12.4.1622
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved