6.8
CVE-2020-26200
- EPSS 0.03%
- Veröffentlicht 26.02.2021 14:15:12
- Zuletzt bearbeitet 21.11.2024 05:19:30
- Quelle vulnerability@kaspersky.com
- Teams Watchlist Login
- Unerledigt Login
A component of Kaspersky custom boot loader allowed loading of untrusted UEFI modules due to insufficient check of their authenticity. This component is incorporated in Kaspersky Rescue Disk (KRD) and was trusted by the Authentication Agent of Full Disk Encryption in Kaspersky Endpoint Security (KES). This issue allowed to bypass the UEFI Secure Boot security feature. An attacker would need physical access to the computer to exploit it. Otherwise, local administrator privileges would be required to modify the boot loader component.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Kaspersky ≫ Endpoint Security Version10 Updatesp2_mr2
Kaspersky ≫ Endpoint Security Version10 Updatesp2_mr3
Kaspersky ≫ Endpoint Security Version11.0.0
Kaspersky ≫ Endpoint Security Version11.0.1
Kaspersky ≫ Endpoint Security Version11.1.0
Kaspersky ≫ Rescue Disk Version < 18.0.11.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.03% | 0.054 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 6.8 | 0.9 | 5.9 |
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.