6.8

CVE-2020-26200

A component of Kaspersky custom boot loader allowed loading of untrusted UEFI modules due to insufficient check of their authenticity. This component is incorporated in Kaspersky Rescue Disk (KRD) and was trusted by the Authentication Agent of Full Disk Encryption in Kaspersky Endpoint Security (KES). This issue allowed to bypass the UEFI Secure Boot security feature. An attacker would need physical access to the computer to exploit it. Otherwise, local administrator privileges would be required to modify the boot loader component.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Kaspersky ≫ Endpoint Security Version 10 Update sp2_mr2
Kaspersky ≫ Endpoint Security Version 10 Update sp2_mr3
Kaspersky ≫ Endpoint Security Version 11.0.0
Kaspersky ≫ Endpoint Security Version 11.0.1
Kaspersky ≫ Endpoint Security Version 11.1.0
Kaspersky ≫ Rescue Disk Version < 18.0.11.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.23% 0.137
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 0.9 5.9
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

https://support.kaspersky.com/general/vulnerability.aspx?el=12430#170221
Broken Link
https://github.com/CVEProject/cvelist/blob/master/2020/26xxx/CVE-2020-26200.json
Third Party Advisory