6.7

CVE-2019-15689

Exploit
Kaspersky Secure Connection, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Security Cloud prior to version 2020 patch E have bug that allows a local user to execute arbitrary code via execution compromised file placed by an attacker with administrator rights. No privilege escalation. Possible whitelisting bypass some of the security products
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Kaspersky ≫ Kaspersky Internet Security Version 2019 Update -
Kaspersky ≫ Kaspersky Internet Security Version 2019 Update patch_f
Kaspersky ≫ Kaspersky Internet Security Version 2019 Update patch_i
Kaspersky ≫ Kaspersky Internet Security Version 2019 Update patch_j
Kaspersky ≫ Secure Connection Version 3.0
Kaspersky ≫ Secure Connection Version 4.0
Kaspersky ≫ Security Cloud Version 2019 Update -
Kaspersky ≫ Security Cloud Version 2019 Update patch_i
Kaspersky ≫ Security Cloud Version 2019 Update patch_j
Kaspersky ≫ Security Cloud Version 2020 Update -
Kaspersky ≫ Total Security Version 2019 Update -
Kaspersky ≫ Total Security Version 2019 Update patch_f
Kaspersky ≫ Total Security Version 2019 Update patch_i
Kaspersky ≫ Total Security Version 2019 Update patch_j
Kaspersky ≫ Total Security Version 2020
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.77% 0.506
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
NIST 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
CWE-668 Exposure of Resource to Wrong Sphere

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

https://support.kaspersky.com/general/vulnerability.aspx?el=12430#021219
Broken Link
https://safebreach.com/Post/Kaspersky-Secure-Connection-DLL-Preloading-and-Potential-Abuses-CVE-2019-15689
Third Party Advisory
Exploit
https://www.symantec.com/security-center/vulnerabilities/writeup/111033
Third Party Advisory