PT-2019-2803 · Kaspersky · Kaspersky Small Office Security+4

Wladimir Palant

·

Published

2019-07-11

·

Updated

2019-08-15

·

CVE-2019-8286

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kaspersky Anti-Virus versions up to 2019 Kaspersky Internet Security versions up to 2019 Kaspersky Total Security versions up to 2019 Kaspersky Free Anti-Virus (affected versions not specified) Kaspersky Small Office Security (affected versions not specified)
Description The issue is related to information disclosure in Kaspersky antivirus products. It could potentially disclose a unique Product ID by forcing the victim to visit a specially crafted webpage, such as via clicking a phishing link. This could allow a remote attacker to reveal protected information using a specially formed web page. The flaw may have allowed online trackers to identify users without using browser cookies.
Recommendations For Kaspersky Anti-Virus versions up to 2019, update to a version later than 2019 to resolve the issue. For Kaspersky Internet Security versions up to 2019, update to a version later than 2019 to resolve the issue. For Kaspersky Total Security versions up to 2019, update to a version later than 2019 to resolve the issue. For Kaspersky Free Anti-Virus, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Kaspersky Small Office Security, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-02758
CVE-2019-8286

Affected Products

Kaspersky Anti-Virus
Kaspersky Free Anti-Virus
Kaspersky Internet Security
Kaspersky Small Office Security
Kaspersky Total Security