PT-2020-3292 · Kaspersky · Kaspersky Anti-Ransomware Tool

Shahee Mirza

·

Published

2020-07-29

·

Updated

2020-12-08

·

CVE-2020-28950

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kaspersky Anti-Ransomware Tool versions prior to 4.0 Patch C
Description The issue is related to errors in the mechanism for checking the path to dynamically loaded libraries (DLL), which can be exploited to elevate privileges during the installation process. This can allow an attacker to perform a DLL hijacking attack.
Recommendations For versions prior to 4.0 Patch C, update to KART 4.0 Patch C to resolve the issue. As a temporary workaround, consider restricting the installation process to minimize the risk of exploitation.

Fix

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-03600
CVE-2020-28950

Affected Products

Kaspersky Anti-Ransomware Tool