PT-2021-2011 · Kaspersky · Kaspersky Endpoint Security+1
Published
2021-02-17
·
Updated
2025-09-14
·
CVE-2020-26200
CVSS v3.1
6.8
Medium
| AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Kaspersky Endpoint Security (affected versions not specified)
Kaspersky Rescue Disk (affected versions not specified)
Description
A component of Kaspersky custom boot loader allowed loading of untrusted UEFI modules due to insufficient check of their authenticity. This issue allowed bypassing the UEFI Secure Boot security feature. An attacker would need physical access to the computer to exploit it, or local administrator privileges would be required to modify the boot loader component.
Recommendations
For Kaspersky Endpoint Security, consider restricting access to the boot loader component until a patch is available.
For Kaspersky Rescue Disk, avoid using it until the issue is resolved.
As a temporary workaround, consider disabling the custom boot loader component in both Kaspersky Endpoint Security and Kaspersky Rescue Disk to minimize the risk of exploitation.
Exploit
Fix
Insufficient Verification of Data Authenticity
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kaspersky Endpoint Security
Kaspersky Rescue Disk