Code Execution Vulnerability in Kaspersky Products Exposes Users
CVE-2019-15689
6.7MEDIUM
Key Information:
- Vendor
- Kaspersky
- Vendor
- CVE Published:
- 2 December 2019
Summary
A vulnerability in Kaspersky Secure Connection, Kaspersky Internet Security, Kaspersky Total Security, and Kaspersky Security Cloud allows a local user to execute arbitrary code. This flaw occurs when an attacker, with administrator rights, places a compromised file on the system. The vulnerability may also enable bypassing certain whitelisting mechanisms, which could undermine the effectiveness of some security features.
Affected Version(s)
Kaspersky Secure Connection, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Security Cloud prior to version 2020 patch E
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved