Medium severity6.7NVD Advisory· Published Dec 2, 2019· Updated Jun 17, 2026
CVE-2019-15689
CVE-2019-15689
Description
Kaspersky Secure Connection, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Security Cloud prior to version 2020 patch E have bug that allows a local user to execute arbitrary code via execution compromised file placed by an attacker with administrator rights. No privilege escalation. Possible whitelisting bypass some of the security products
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
19cpe:2.3:a:kaspersky:kaspersky_internet_security:2019:-:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:kaspersky:kaspersky_internet_security:2019:-:*:*:*:*:*:*
- cpe:2.3:a:kaspersky:kaspersky_internet_security:2019:patch_f:*:*:*:*:*:*
- cpe:2.3:a:kaspersky:kaspersky_internet_security:2019:patch_i:*:*:*:*:*:*
- cpe:2.3:a:kaspersky:kaspersky_internet_security:2019:patch_j:*:*:*:*:*:*
cpe:2.3:a:kaspersky:secure_connection:3.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:kaspersky:secure_connection:3.0:*:*:*:*:*:*:*
- cpe:2.3:a:kaspersky:secure_connection:4.0:*:*:*:*:*:*:*
- (no CPE)range: <2020 patch E
cpe:2.3:a:kaspersky:security_cloud:2019:-:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:kaspersky:security_cloud:2019:-:*:*:*:*:*:*
- cpe:2.3:a:kaspersky:security_cloud:2019:patch_i:*:*:*:*:*:*
- cpe:2.3:a:kaspersky:security_cloud:2019:patch_j:*:*:*:*:*:*
- cpe:2.3:a:kaspersky:security_cloud:2020:-:*:*:*:*:*:*
cpe:2.3:a:kaspersky:total_security:2019:-:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:kaspersky:total_security:2019:-:*:*:*:*:*:*
- cpe:2.3:a:kaspersky:total_security:2019:patch_f:*:*:*:*:*:*
- cpe:2.3:a:kaspersky:total_security:2019:patch_i:*:*:*:*:*:*
- cpe:2.3:a:kaspersky:total_security:2019:patch_j:*:*:*:*:*:*
- cpe:2.3:a:kaspersky:total_security:2020:*:*:*:*:*:*:*
- (no CPE)range: <2020 patch E
- Range: <2020 patch E
- Kaspersky/Kaspersky Secure Connection, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Security Cloudv5Range: prior to version 2020 patch E
Patches
Vulnerability mechanics
References
3- safebreach.com/Post/Kaspersky-Secure-Connection-DLL-Preloading-and-Potential-Abuses-CVE-2019-15689nvdExploitThird Party Advisory
- www.symantec.com/security-center/vulnerabilities/writeup/111033nvdThird Party Advisory
- support.kaspersky.com/general/vulnerability.aspxnvdBroken Link
News mentions
0No linked articles in our index yet.