PT-2022-2063 · Kaspersky · Kaspersky Internet Security+5

Georgy Zaytsev

·

Published

2022-03-31

·

Updated

2022-04-08

·

CVE-2022-27534

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security versions prior to 12 March 2022 Kaspersky Internet Security versions prior to 12 March 2022 Kaspersky Total Security versions prior to 12 March 2022 Kaspersky Small Office Security versions prior to 12 March 2022 Kaspersky Security Cloud versions prior to 12 March 2022
Description The issue is related to a bug in a data parsing module of Kaspersky Anti-Virus products, which potentially allowed an attacker to execute arbitrary code. This bug is also associated with unlimited resource allocation. The exploitation of this issue may allow a remote attacker to execute arbitrary code.
Recommendations For Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security versions prior to 12 March 2022, the fix was delivered automatically. For Kaspersky Internet Security versions prior to 12 March 2022, consider updating to a version released after 12 March 2022. For Kaspersky Total Security versions prior to 12 March 2022, consider updating to a version released after 12 March 2022. For Kaspersky Small Office Security versions prior to 12 March 2022, consider updating to a version released after 12 March 2022. For Kaspersky Security Cloud versions prior to 12 March 2022, consider updating to a version released after 12 March 2022.

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-01730
CVE-2022-27534

Affected Products

Kaspersky Anti-Virus
Kaspersky Endpoint Security
Kaspersky Internet Security
Kaspersky Security Cloud
Kaspersky Small Office Security
Kaspersky Total Security