CVE-2020-25043

7.1HIGH

Key Information:

Vendor
Kaspersky
Vendor
CVE Published:
2 September 2020

Summary

The installer of Kaspersky VPN Secure Connection prior to 5.0 was vulnerable to arbitrary file deletion that could allow an attacker to delete any file in the system.

Affected Version(s)

Kaspersky VPN Secure Connection prior to 5.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.