Kaspersky Lab
Kaspersky Lab is a Russian multinational cybersecurity and anti-virus provider company headquartered in Moscow, Russia. It was founded in 1997 by Eugene Kaspersky, Natalya Kaspersky and Alexey De-Monderik. Kaspersky Lab develops and sells antivirus, endpoint security, SIEM, XDR, and other cybersecurity products and services. The Kaspersky Global Research and Analysis Team (GReAT) has led the discovery of sophisticated espionage platforms conducted by nations, such as Equation Group and the Stuxnet worm. Their research has uncovered large-scale and highly technical cyber espionage attempts.
Products
54- 52 CVEs
- 31 CVEs
- 12 CVEs
- 11 CVEs
- 10 CVEs
- 7 CVEs
- 7 CVEs
- 7 CVEs
- 6 CVEs
- 5 CVEs
- 4 CVEs
- 4 CVEs
- 4 CVEs
- 4 CVEs
- 3 CVEs
- 3 CVEs
- 3 CVEs
- 3 CVEs
- 3 CVEs
- 3 CVEs
- 2 CVEs
- 2 CVEs
- 2 CVEs
- 2 CVEs
- 2 CVEs
- 2 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- View all 54 products →
Recent CVEs
103| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-9811 | Cri | 0.68 | 9.8 | 0.10 | Jul 17, 2017 | The kluser is able to interact with the kav4fs-control binary in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312). By abusing the quarantine read and write operations, it is possible to elevate the privileges to root. | ||
| CVE-2022-27534 | Cri | 0.64 | 9.8 | 0.03 | Apr 1, 2022 | Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security with antivirus databases released before 12 March 2022 had a bug in a data parsing module that potentially allowed an attacker to execute arbitrary code. The fix was delivered automatically. Credits: Georgy… | ||
| CVE-2020-36199 | Cri | 0.64 | 9.8 | 0.02 | Jan 26, 2021 | TinyCheck before commits 9fd360d and ea53de8 was vulnerable to command injection due to insufficient checks of input parameters in several places. | ||
| CVE-2020-35929 | Cri | 0.64 | 9.8 | 0.01 | Jan 19, 2021 | In TinyCheck before commits 9fd360d and ea53de8, the installation script of the tool contained hard-coded credentials to the backend part of the tool. This information could be used by an attacker for unauthorized access to remote data. | ||
| CVE-2018-6289 | Cri | 0.64 | 9.8 | 0.07 | Feb 6, 2018 | Configuration file injection leading to Code Execution as Root in Kaspersky Secure Mail Gateway version 1.1. | ||
| CVE-2017-12816 | Cri | 0.64 | 9.8 | 0.02 | Aug 25, 2017 | In Kaspersky Internet Security for Android 11.12.4.1622, some of application exports activities have weak permissions, which might be used by a malware application to get unauthorized access to the product functionality by using Android IPC. | ||
| CVE-2017-9810 | Hig | 0.60 | 8.8 | 0.02 | Jul 17, 2017 | There are no Anti-CSRF tokens in any forms on the web interface in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312). This would allow an attacker to submit authenticated requests when an authenticated user browses an… | ||
| CVE-2019-8285 | Hig | 0.58 | 8.8 | 0.04 | May 8, 2019 | Kaspersky Lab Antivirus Engine version before 04.apr.2019 has a heap-based buffer overflow vulnerability that potentially allow arbitrary code execution | ||
| CVE-2018-6288 | Hig | 0.57 | 8.8 | 0.01 | Feb 6, 2018 | Cross-site Request Forgery leading to Administrative account takeover in Kaspersky Secure Mail Gateway version 1.1. | ||
| CVE-2017-9812 | Hig | 0.53 | 7.5 | 0.11 | Jul 17, 2017 | The reportId parameter of the getReportStatus action method can be abused in the web interface in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312) to read arbitrary files with kluser privileges. | ||
| CVE-2022-27535 | Hig | 0.51 | 7.8 | 0.00 | Aug 5, 2022 | Kaspersky VPN Secure Connection for Windows version up to 21.5 was vulnerable to arbitrary file deletion via abuse of its 'Delete All Service Data And Reports' feature by the local authenticated attacker. | ||
| CVE-2021-35052 | Hig | 0.51 | 7.8 | 0.00 | Nov 23, 2021 | A component in Kaspersky Password Manager could allow an attacker to elevate a process Integrity level from Medium to High. | ||
| CVE-2020-28950 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2020 | The installer of Kaspersky Anti-Ransomware Tool (KART) prior to KART 4.0 Patch C was vulnerable to a DLL hijacking attack that allowed an attacker to elevate privileges during installation process. | ||
| CVE-2020-25045 | Hig | 0.51 | 7.8 | 0.00 | Sep 2, 2020 | Installers of Kaspersky Security Center and Kaspersky Security Center Web Console prior to 12 & prior to 12 Patch A were vulnerable to a DLL hijacking attack that allowed an attacker to elevate privileges in the system. | ||
| CVE-2018-6306 | Hig | 0.51 | 7.8 | 0.03 | Apr 19, 2018 | Unauthorized code execution from specific DLL and is known as DLL Hijacking attack in Kaspersky Password Manager versions before 8.0.6.538. | ||
| CVE-2018-6290 | Hig | 0.51 | 7.8 | 0.00 | Feb 6, 2018 | Local Privilege Escalation in Kaspersky Secure Mail Gateway version 1.1. | ||
| CVE-2017-12823 | Hig | 0.51 | 7.8 | 0.00 | Dec 8, 2017 | Kernel pool memory corruption in one of drivers in Kaspersky Embedded Systems Security version 1.2.0.300 leads to local privilege escalation. | ||
| CVE-2021-35053 | Hig | 0.49 | 7.5 | 0.03 | Nov 3, 2021 | Possible system denial of service in case of arbitrary changing Firefox browser parameters. An attacker could change specific Firefox browser parameters file in a certain way and then reboot the system to make the system unbootable. | ||
| CVE-2020-27020 | Hig | 0.49 | 7.5 | 0.01 | May 14, 2021 | Password generator feature in Kaspersky Password Manager was not completely cryptographically strong and potentially allowed an attacker to predict generated passwords in some cases. An attacker would need to know some additional information (for example, time of password… | ||
| CVE-2017-12817 | Hig | 0.49 | 7.5 | 0.01 | Aug 25, 2017 | In Kaspersky Internet Security for Android 11.12.4.1622, some of the application trace files were not encrypted. |
- risk 0.68cvss 9.8epss 0.10
The kluser is able to interact with the kav4fs-control binary in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312). By abusing the quarantine read and write operations, it is possible to elevate the privileges to root.
- risk 0.64cvss 9.8epss 0.03
Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security with antivirus databases released before 12 March 2022 had a bug in a data parsing module that potentially allowed an attacker to execute arbitrary code. The fix was delivered automatically. Credits: Georgy…
- risk 0.64cvss 9.8epss 0.02
TinyCheck before commits 9fd360d and ea53de8 was vulnerable to command injection due to insufficient checks of input parameters in several places.
- risk 0.64cvss 9.8epss 0.01
In TinyCheck before commits 9fd360d and ea53de8, the installation script of the tool contained hard-coded credentials to the backend part of the tool. This information could be used by an attacker for unauthorized access to remote data.
- risk 0.64cvss 9.8epss 0.07
Configuration file injection leading to Code Execution as Root in Kaspersky Secure Mail Gateway version 1.1.
- risk 0.64cvss 9.8epss 0.02
In Kaspersky Internet Security for Android 11.12.4.1622, some of application exports activities have weak permissions, which might be used by a malware application to get unauthorized access to the product functionality by using Android IPC.
- risk 0.60cvss 8.8epss 0.02
There are no Anti-CSRF tokens in any forms on the web interface in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312). This would allow an attacker to submit authenticated requests when an authenticated user browses an…
- risk 0.58cvss 8.8epss 0.04
Kaspersky Lab Antivirus Engine version before 04.apr.2019 has a heap-based buffer overflow vulnerability that potentially allow arbitrary code execution
- risk 0.57cvss 8.8epss 0.01
Cross-site Request Forgery leading to Administrative account takeover in Kaspersky Secure Mail Gateway version 1.1.
- risk 0.53cvss 7.5epss 0.11
The reportId parameter of the getReportStatus action method can be abused in the web interface in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312) to read arbitrary files with kluser privileges.
- risk 0.51cvss 7.8epss 0.00
Kaspersky VPN Secure Connection for Windows version up to 21.5 was vulnerable to arbitrary file deletion via abuse of its 'Delete All Service Data And Reports' feature by the local authenticated attacker.
- risk 0.51cvss 7.8epss 0.00
A component in Kaspersky Password Manager could allow an attacker to elevate a process Integrity level from Medium to High.
- risk 0.51cvss 7.8epss 0.00
The installer of Kaspersky Anti-Ransomware Tool (KART) prior to KART 4.0 Patch C was vulnerable to a DLL hijacking attack that allowed an attacker to elevate privileges during installation process.
- risk 0.51cvss 7.8epss 0.00
Installers of Kaspersky Security Center and Kaspersky Security Center Web Console prior to 12 & prior to 12 Patch A were vulnerable to a DLL hijacking attack that allowed an attacker to elevate privileges in the system.
- risk 0.51cvss 7.8epss 0.03
Unauthorized code execution from specific DLL and is known as DLL Hijacking attack in Kaspersky Password Manager versions before 8.0.6.538.
- risk 0.51cvss 7.8epss 0.00
Local Privilege Escalation in Kaspersky Secure Mail Gateway version 1.1.
- risk 0.51cvss 7.8epss 0.00
Kernel pool memory corruption in one of drivers in Kaspersky Embedded Systems Security version 1.2.0.300 leads to local privilege escalation.
- risk 0.49cvss 7.5epss 0.03
Possible system denial of service in case of arbitrary changing Firefox browser parameters. An attacker could change specific Firefox browser parameters file in a certain way and then reboot the system to make the system unbootable.
- risk 0.49cvss 7.5epss 0.01
Password generator feature in Kaspersky Password Manager was not completely cryptographically strong and potentially allowed an attacker to predict generated passwords in some cases. An attacker would need to know some additional information (for example, time of password…
- risk 0.49cvss 7.5epss 0.01
In Kaspersky Internet Security for Android 11.12.4.1622, some of the application trace files were not encrypted.