PT-2021-2527 · Kaspersky · Kis For Macos

Csaba Fitzl

+1

·

Published

2021-03-31

·

Updated

2021-04-07

·

CVE-2021-26718

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: KIS for macOS (affected versions not specified)
Description: The issue is related to an error in the authorization procedure of the XPC service of Kaspersky Internet Security for macOS, which could potentially allow an attacker to disable anti-virus protection. This could be exploited to bypass anti-virus measures in certain use cases.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-01933
CVE-2021-26718

Affected Products

Kis For Macos