PT-2019-4503 · Kaspersky+1 · Kaspersky Security Cloud+6

Wladimir Palant

·

Publicado

2019-11-25

·

Atualizado

2021-07-21

·

CVE-2019-15687

CVSS v2.0

7.1

Alta

VetorAV:N/AC:M/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kaspersky Anti-Virus versions up to 2020 Kaspersky Internet Security versions up to 2020 Kaspersky Total Security versions up to 2020 Kaspersky Free Anti-Virus versions up to 2020 Kaspersky Small Office Security versions up to 2020 Kaspersky Security Cloud versions up to 2020
Description The web protection component of the affected Kaspersky products was vulnerable to remote disclosure of various information about the user's system, including Windows version, product version, and host unique ID. This issue is related to the lack of protection for service data, which could allow a remote attacker to disclose protected information.
Recommendations For Kaspersky Anti-Virus versions up to 2020, update to a version later than 2020 to resolve the issue. For Kaspersky Internet Security versions up to 2020, update to a version later than 2020 to resolve the issue. For Kaspersky Total Security versions up to 2020, update to a version later than 2020 to resolve the issue. For Kaspersky Free Anti-Virus versions up to 2020, update to a version later than 2020 to resolve the issue. For Kaspersky Small Office Security versions up to 2020, update to a version later than 2020 to resolve the issue. For Kaspersky Security Cloud versions up to 2020, update to a version later than 2020 to resolve the issue.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-00363
CVE-2019-15687

Produtos afetados

Kaspersky Anti-Virus
Kaspersky Free Anti-Virus
Kaspersky Internet Security
Kaspersky Security Cloud
Kaspersky Small Office Security
Kaspersky Total Security
Windows