Arbitrary File Corruption Vulnerability in Kaspersky Virus Removal Tool
CVE-2020-25044
7.1HIGH
Key Information:
- Vendor
- Kaspersky
- Vendor
- CVE Published:
- 2 September 2020
Summary
The Kaspersky Virus Removal Tool, specifically versions prior to 15.0.23.0, is vulnerable to an arbitrary file corruption flaw. This vulnerability may allow an attacker to manipulate and eliminate the contents of any file on the affected system, posing significant risks to data integrity and security.
Affected Version(s)
Kaspersky Virus Removal Tool prior to 15.0.23.0
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved