6.7
CVE-2019-15689
- EPSS 0.77%
- Veröffentlicht 02.12.2019 21:15:16
- Zuletzt bearbeitet 21.11.2024 04:29:15
- Erkennungen
Kaspersky Secure Connection, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Security Cloud prior to version 2020 patch E have bug that allows a local user to execute arbitrary code via execution compromised file placed by an attacker with administrator rights. No privilege escalation. Possible whitelisting bypass some of the security products
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Kaspersky ≫ Kaspersky Internet Security Version 2019 Update -
Kaspersky ≫ Kaspersky Internet Security Version 2019 Update patch_f
Kaspersky ≫ Kaspersky Internet Security Version 2019 Update patch_i
Kaspersky ≫ Kaspersky Internet Security Version 2019 Update patch_j
Kaspersky ≫ Secure Connection Version 3.0
Kaspersky ≫ Secure Connection Version 4.0
Kaspersky ≫ Security Cloud Version 2019 Update -
Kaspersky ≫ Security Cloud Version 2019 Update patch_i
Kaspersky ≫ Security Cloud Version 2019 Update patch_j
Kaspersky ≫ Security Cloud Version 2020 Update -
Kaspersky ≫ Total Security Version 2019 Update -
Kaspersky ≫ Total Security Version 2019 Update patch_f
Kaspersky ≫ Total Security Version 2019 Update patch_i
Kaspersky ≫ Total Security Version 2019 Update patch_j
Kaspersky ≫ Total Security Version 2020
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.77% | 0.506 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
CWE-668 Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
https://support.kaspersky.com/general/vulnerability.aspx?el=12430#021219
https://safebreach.com/Post/Kaspersky-Secure-Connection-DLL-Preloading-and-Potential-Abuses-CVE-2019-15689
https://www.symantec.com/security-center/vulnerabilities/writeup/111033