PT-2022-5288 · Kaspersky · Kavremover+1

Published

2022-11-01

·

Updated

2022-11-01

CVSS v2.0

1.7

Low

VectorAV:L/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Kaspersky Endpoint Security (affected versions not specified) Kavremover (affected versions not specified)
Description The issue is related to an uncontrolled search path element in the installation file of Kaspersky Endpoint Security and the Kavremover utility. Exploitation of this issue may allow an attacker to run a third-party executable file in the context of the installation process.
Recommendations For Kaspersky Endpoint Security, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Kavremover, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

BDU:2022-06573

Affected Products

Kaspersky Endpoint Security
Kavremover