PT-2022-2063 · Kaspersky · Kaspersky Internet Security+5
Georgy Zaytsev
·
Published
2022-03-31
·
Updated
2022-04-08
·
CVE-2022-27534
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security versions prior to 12 March 2022
Kaspersky Internet Security versions prior to 12 March 2022
Kaspersky Total Security versions prior to 12 March 2022
Kaspersky Small Office Security versions prior to 12 March 2022
Kaspersky Security Cloud versions prior to 12 March 2022
Description
The issue is related to a bug in a data parsing module of Kaspersky Anti-Virus products, which potentially allowed an attacker to execute arbitrary code. This bug is also associated with unlimited resource allocation. The exploitation of this issue may allow a remote attacker to execute arbitrary code.
Recommendations
For Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security versions prior to 12 March 2022, the fix was delivered automatically.
For Kaspersky Internet Security versions prior to 12 March 2022, consider updating to a version released after 12 March 2022.
For Kaspersky Total Security versions prior to 12 March 2022, consider updating to a version released after 12 March 2022.
For Kaspersky Small Office Security versions prior to 12 March 2022, consider updating to a version released after 12 March 2022.
For Kaspersky Security Cloud versions prior to 12 March 2022, consider updating to a version released after 12 March 2022.
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kaspersky Anti-Virus
Kaspersky Endpoint Security
Kaspersky Internet Security
Kaspersky Security Cloud
Kaspersky Small Office Security
Kaspersky Total Security