12430
Kaspersky appreciates the ongoing efforts of the independent researchers that help us make our products and solutions more efficient and better protected. Below you can find a list of disclosed vulnerabilities and researchers that reported them to us.
Advisory issued on September 17, 2026
Kaspersky has fixed a vulnerability in third‑party components ( CVE-2023-41056 ) used in Kaspersky Security 10 for Linux Mail Server version 10.0. The vulnerability could potentially cause product malfunction or allow an attacker to execute code when processing files of a certain format.
Affected applications
Kaspersky Security 10 for Linux Mail Server version 10.0
Kaspersky Secure Mail Gateway version 3.1
To remediate the vulnerability, install Kaspersky Secure Mail Gateway version 3.1, which provides identical functionality. To obtain the distribution package, Kaspersky Support.
Advisory issued on August 31, 2026
Kaspersky has fixed the issue described in the HardBreacher research. The described issue could potentially have resulted in a partial degradation of the application functionality. The issue was mitigated by updating the antivirus databases.
Affected applications
Kaspersky Endpoint Security Windows versions 14.0 and 14.1
Kaspersky Endpoint Security Windows versions 14.0 and 14.1 with antivirus databases released on August 30, 2026, and later.
We recommend our users check the antivirus database update date in the application.
Advisory issued on May 29, 2026
Kaspersky has fixed a vulnerability in third-party components ( CVE-2026-31932 ) used in Kaspersky Anti Targeted Attack Platform version 8.0.
The vulnerability could potentially result in product performance degradation when processing specially crafted network traffic.
Affected applications
Kaspersky Anti Targeted Attack Platform version 8.0
Kaspersky Anti Targeted Attack Platform version 8.0.1
To fix the vulnerability, you need to install an application update (Kaspersky Anti Targeted Attack Platform version 8.0.1). To do this, follow the instructions .
Advisory issued on May 26, 2026
Kaspersky has fixed vulnerabilities in third-party components ( CVE-2026-28348 , CVE-2026-28350 ) used in Kaspersky Anti Targeted Attack Platform version 7.1.1 patch A.
The vulnerabilities could potentially cause the application malfunction when unpacking files of a certain format.
Affected applications
Kaspersky Anti Targeted Attack Platform version 7.1.3
Kaspersky Anti Targeted Attack Platform version 7.1.2
Kaspersky Anti Targeted Attack Platform version 7.1.1 patch A
Kaspersky Anti Targeted Attack Platform version 7.1.7
To fix the vulnerabilities, you need to install an application update (Kaspersky Anti Targeted Attack Platform version 7.1.7). Technical Support to obtain the update.
Advisory issued on May 8, 2026
Official statement by Kaspersky regarding the Linux kernel vulnerabilities CVE-2026-43284, CVE-2026-43500, CVE-2026-46300
Kaspersky server applications running on Linux with default settings are not affected by the Linux kernel vulnerabilities CVE-2026-43284 and CVE-2026-43500 , collectively known as Dirty Frag, or by CVE-2026-46300 , known as Fragnesia.
Since these vulnerabilities have been identified in operating system modules that our applications closely interact with, Kaspersky experts have tested the recommended mitigation measures (workarounds) and confirmed that they can be applied to the company’s solutions on Linux without affecting their functionality.
Kaspersky experts recommend installing Linux updates as soon as possible. If this is not possible, the mitigation measures must be applied.
Kaspersky Secure Mail Gateway
Kaspersky Automated Security Awareness Platform
Kaspersky Private Security Network
Kaspersky Web Traffic Security
Kaspersky Generation Firewall
Kaspersky Industrial CyberSecurity for Networks
Kaspersky Unified Monitoring and Analysis Platform
Kaspersky Extended Detection and Response
Kaspersky Rescue Disk
Kaspersky Security for Virtualization Light Agent
Advisory issued on May 5, 2026
Kaspersky has fixed a vulnerability in third-party components ( CVE-2023-28322 ) used in Kaspersky Industrial Cyber Security for Nodes 2.6.0.785.
The vulnerability could potentially cause the product malfunction when its components interact.
Affected applications
Kaspersky Industrial CyberSecurity for Nodes 2.6.0.785.
Kaspersky Industrial CyberSecurity for Nodes 4.0.0.236.
To fix the vulnerability, you need to install a product update (Kaspersky Industrial Cyber Security for Nodes 4.0.0.236). Technical Support to obtain the update.
Advisory issued on May 1, 2026
Official statement by Kaspersky regarding the Linux kernel vulnerability CVE-2026-31431 (copy.fail)
The Linux kernel vulnerability CVE-2026-31431 , also known as copy.fail , does not affect the operation of Kaspersky server applications running on the Linux operating system when used with default settings.
Since this vulnerability has been identified in operating system modules that our applications closely interact with, Kaspersky experts have tested the recommended mitigation measures (workarounds) and confirmed that they can be applied to the company’s solutions on Linux without affecting their functionality.
Kaspersky experts recommend installing Linux updates as soon as possible. If this is not possible, the algif_aead kernel module must be disabled .
Kaspersky Anti Targeted Attack Platform
Kaspersky Security for Virtualization Light Agent
Kaspersky SD-WAN CORE
Kaspersky Private Security Network
Kaspersky Container Security
Kaspersky Secure Mail Gateway (follow the instructions )
Kaspersky Web Traffic Security (follow the instructions )
Kaspersky Industrial CyberSecurity for Networks (follow the instructions )
Advisory issued on March 16, 2026
Kaspersky has fixed a vulnerability in third-party components ( CVE-2018-25032 , CVE-2021-42260 ) used in Kaspersky Security for Virtual Environments Light Agent Version 5.2.
The vulnerability could potentially cause the product malfunction when unpacking files of a certain format.
Affected applications
Kaspersky Security for Virtual Environments Light Agent Version 5.2 for Windows and Linux
Kaspersky Security for Virtual Environments Light Agent Version 5.2 pf225 for Windows (eng)
Kaspersky Security for Virtual Environments Light Agent Version 5.2 pf226 for Windows (fr)
Kaspersky Security for Virtual Environments Light Agent Version 5.2 pf227 for Windows (de)
Kaspersky Security for Virtual Environments Light Agent Version 5.2.27-1843 for Linux
To fix the vulnerability, you need to install a product update. support to obtain the update.
Advisory issued on November 24, 2025
Kaspersky has fixed a security issue that could occur during the installation of Kaspersky Security Center for Windows, caused by insufficient validation of dynamically loaded libraries. This issue could allow an adversary to affect the integrity of the installation package.
Already installed versions of application are not affected by this problem.
Affected applications
Only the application versions listed in the table below are affected.
Already installed versions of application are not affected by this problem.
We would like to thank Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc. , and the JPCERT/CC Vulnerability Coordination Group for discovering this issue and responsibly disclosing it.
Advisory issued on November 18, 2025
Kaspersky has fixed a security issue that could have allowed a reflected XSS attack to be carried out by an attacker using phishing techniques.
5.1 ( CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N )
Affected applications
Only the application versions listed in the table below are vulnerable.
12.2.0.694 with anti-virus databases prior to 18.11.2025
Users of versions 12.0.0.325 and 12.1.0.553 are recommended to update the application to version 12.2.0.694 with the latest version of the anti-virus databases.
Users of version 12.2.0.694 have access to an automated update within the current version (antivirus databases released on 18.11.2025, and later), which mitigates this issue.
Advisory issued on August 12, 2025
Kaspersky has fixed a vulnerability in the applications using antivirus databases that could potentially lead to the execution of arbitrary code on a user’s device. The vulnerability fix was delivered to all Kaspersky customers automatically as part of the update of antivirus databases. Kaspersky has not observed any active exploitation of this vulnerability in the wild.
Affected applications
Kaspersky applications with antivirus databases.
Kaspersky applications for Windows with antivirus databases released on 4th August, 2025, and later.
Kaspersky applications for Linux, macOS, and FreeBSD with antivirus databases released on 8th August, 2025, and later.
The fix was installed automatically for all Kaspersky customers.
We recommend our users check the antivirus database update date.
We would like to thank Georgy Zaytsev from Positive Technologies who discovered this issue and responsibly disclosed it.
Advisory issued on April 1, 2025
Kaspersky has fixed security issues in dependent components of its applications.
Affected applications
Only the application versions listed in the table below are vulnerable.
Advisory issued on February 6, 2025
Kaspersky has fixed a security issue that could allow an authenticated attacker to write data to a limited area outside the allocated kernel memory buffer. There have been no recorded attempts to exploit this issue in the wild.
6.9 ( CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:L/SA:H )
5.3 ( CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H )
5.3 ( CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H )
Affected applications Application Recommendations Kaspersky Anti-Virus SDK for Windows The issue affects only KAV SDK 8.10.1.1943 and 8.10.1.1943 CF. To fix the issue, upgrade the KAV SDK to the following version: Kaspersky Anti-Virus Software Development Kit 8 Level 3 v. 8.10.2.2098. your Technical Account Manager to obtain the necessary instructions. Kaspersky Security for Virtualization Light Agent The issue affects the versions of KSV Light Agent 5.2 up to version 5.2.27.319 with the component "Kaspersky Security Components Installation Wizard" up to version 5.2.1.4004 (ksvla-components_5.2.1.4004_mlg.exe) inclusive. The issue has been fixed starting with the component version "Kaspersky Security Components Installation Wizard" 5.2.1.4005 (ksvla-components_5.2.1.4005_mlg.exe) from KSV Light Agent 5.2.27.319 available for download at the link . To resolve the issue, install Light Agent for Windows with the fix on all virtual machines running the version using the instructions . Kaspersky Endpoint Security for Windows Kaspersky Small Office Security Kaspersky for Windows (Standard, Plus, Premium) Kaspersky Free Kaspersky Anti-Virus Kaspersky Internet Security Kaspersky Security Cloud Kaspersky Safe Kids Kaspersky Anti-Ransomware The fix was installed automatically for all applications from the list with antivirus databases older than November 5, 2024. To check for the fix, check the antivirus database update date, it should be November 6, 2024 or newer. Acknowledgments We would like to thank Florian Schweins, who discovered this issue and responsibly disclosed it.
Affected applications
Kaspersky Endpoint Security for Windows
Kaspersky Small Office Security
Kaspersky for Windows (Standard, Plus, Premium)
Kaspersky Internet Security
Kaspersky Security Cloud
Kaspersky Anti-Ransomware
We would like to thank Florian Schweins, who discovered this issue and responsibly disclosed it.
Advisory issued on January 22, 2025
Kaspersky has fixed a security issue that allowed an attacker with local administrator rights to delete arbitrary files and registry keys.
This issue does not add additional capabilities to an attacker with administrative privileges to damage the attacked system. However, we take the security of our applications seriously and are improving our products to minimize risks for users.
4.4 ( CVSS:3.1/AV:L/PR:H/S:U/I:H/AC:L/UI:N/C:N/A:N )
Affected applications
Kaspersky Virus Removal Tool for Windows
Kaspersky Endpoint Security for Windows
Kaspersky Security for Virtualization Light Agent
Kaspersky Anti-Virus SDK for Windows
Kaspersky Small Office Security
Kaspersky for Windows (Standard, Plus, Premium)
Kaspersky Internet Security
Kaspersky Total Security
Kaspersky Security Cloud
The fix was installed automatically for all applications from the list above with antivirus databases older than August 01, 2024.
To facilitate the process of receiving updates, our products support automatic updates. To verify the presence of the fix, check the antivirus database update date, it must be August 02, 2024 or later.
We would like to thank Alice Climent-Pommeret, who discovered this issue and responsibly disclosed it.
Advisory issued on July 12, 2024
Kaspersky recommendations for its applications regarding the security issue CVE-2024-6387 (known as regreSSHion) found in OpenSSH's server (sshd)
We recommend that users follow the instructions below:
Install a patch that fixes the vulnerability. Download Security Patch A from the Kaspersky Secure Mail Gateway → Additional distributive section.
If it is not possible to install the patch, edit the LoginGraceTime parameter (sshd_config):
Open /etc/ssh/sshd_config.
Set the LoginGraceTime parameter: LoginGraceTime 0
Save /etc/ssh/sshd_config.
Restart the sshd service: systemctl restart sshd.service
Edit the LoginGraceTime parameter (sshd_config):
Open /etc/ssh/sshd_config.
Set the LoginGraceTime parameter: LoginGraceTime 0
Save /etc/ssh/sshd_config.
Restart the sshd service: systemctl restart sshd.service
Advisory issued on March 26, 2024
Kaspersky has fixed security issues in dependent components of Kaspersky Anti Targeted Attack version 6.0.0/6.0.1.
Specifically, CVE-2024-23839, CVE-2024-23836, CVE-2024-23837, CVE-2024-24568 have been mitigated in Kaspersky Anti Targeted Attack use scenarios.
Affected applications
Kaspersky Anti Targeted Attack 6.0.1 and earlier
Kaspersky Anti Targeted Attack 6.0.2
We recommend the users of Kaspersky Anti Targeted Attack version 6.0.1 and earlier to install Kaspersky Anti Targeted Attack version 6.0.2.
Advisory issued on March 19, 2024
Kaspersky has fixed a security issue in the kavremover tool for removing Kaspersky applications that allowed an attacker with local administrator rights to access the administrator credentials of the application being removed.
Affected applications
The kavremover tool prior to version 1.0.4308.0
The kavremover tool version 1.0.4308.0
We recommend using only the latest tool version. Do not use the tool unless Kaspersky Customer Service recommends it. Unreasonable using of the tool may complicate the application removal. The latest version of kavremover is available in this article .
We would like to thank Kirill Golobochansky, Philip Zabolotny, and Anna Shestakova from Acribia.ru, who discovered this issue and responsibly disclosed it.
Advisory issued on March 18, 2024
Kaspersky has fixed a security issue in Kaspersky Password Manager (KPM) for Windows that allowed to recover the auto-filled credentials from a memory dump when the KPM extension for Google Chrome is used. To exploit the issue, an attacker must trick a user into visiting a login form of a website with the saved credentials, and the KPM extension must autofill these credentials. The attacker must then launch a malware module to steal those specific credentials. It is recommended to use our EPP solution , which prevents attempts to compromise sensitive data from KPM.
Affected applications
Kaspersky Password Manager for Windows prior to 24.0.0.427
Kaspersky Password Manager for Windows 24.0.0.427
The new version is delivered automatically. To check the version number, use these instructions .
We would like to thank Efstratios Chatzoglou, Zisis Tsiatsikas and Vyron Kampourakis who discovered this issue and responsibly disclosed it.
Advisory issued on February 21, 2024
Kaspersky has fixed a security issue in Kaspersky Endpoint Security for Windows version 12.2 and earlier. This issue allowed application protection modules to be temporarily suspended when installing or reinstalling the application.
Affected applications
Kaspersky Endpoint Security for Windows version 12.2
Kaspersky Endpoint Security for Windows version 12.1 (with anti-virus databases prior to 21.02.2024) and earlier
Kaspersky Endpoint Security for Windows version 12.3
Kaspersky Endpoint Security for Windows version 12.1 (with anti-virus databases dated 21.02.2024 and later)
If you are using Kaspersky Endpoint Security for Windows version 12.2 and earlier, we recommend to update the application to version 12.3. Users of Kaspersky Endpoint Security for Windows version 12.1 have access to an automatic update within the current version (anti-virus databases must be later than 21.02.2024), which mitigates the issue.
We would like to thank Anton Kuznetsov who discovered this issue and responsibly disclosed it.
Advisory issued on February 19, 2024
Kaspersky has fixed security issues in dependent components of Kaspersky Anti Targeted Attack version 6.0. Specifically, CVE-2023-48795 was mitigated in Kaspersky Anti Targeted Attack use scenarios.
Affected applications
Kaspersky Anti Targeted Attack 6.0 and earlier
Kaspersky Anti Targeted Attack 6.0.1 Patch A
We recommend the users of Kaspersky Anti Targeted Attack version 6.0 and earlier to install Kaspersky Anti Targeted Attack version 6.0.1 Patch A. If it is not possible to update the application, use the instructions to mitigate CVE-2023-48795 in Kaspersky Anti Targeted Attack version 6.0 and earlier.
Advisory issued on February 1, 2024
Kaspersky has fixed a security issue in the outdated version of Kaspersky Security for Linux Mail Server. The issue was that an attacker could potentially force an administrator to click on a malicious link to perform unauthorized actions.
If updating the application is not possible, Kaspersky recommends that administrators of Kaspersky Security for Linux Mail Server 8 use two separate browsers: one to manage the application and the other one to visit third-party websites. In other cases, we recommend installing the latest version with the fix .
Affected applications
Kaspersky Security for Linux Mail Server 8 (released on May 14, 2018)
Kaspersky Security for Linux Mail Server 10
We would like to thank Adrian Tiron and Bogdan Tiron who discovered this issue and responsibly disclosed it.
Advisory issued on November 1, 2022
Kaspersky team has fixed three security issues in the installers of Kaspersky products for , the Kavremover tool, and Kaspersky Endpoint Security.
Two reported issues relate to two executables from the products’ installers that could be utilized separately from the product. This security issue allowed an attacker to legitimately run a third-party executable in the context of the installation process. We access the severity of these issues as Low.
The third issue allowed an attacker to unnoticeably run an adversarial executable instead of running the uninstaller intended to remove the third-party security products when installing Kaspersky solutions. To exploit this issue, the attacker needed administrator rights and had to create registry keys pointing to the file they wanted to execute. We access the severity of this issue as Low.
We recommend our customers to use the latest versions of the installers from our website. The users of already installed products are not affected by these issues. Also, we recommend the users who can’t use the latest versions of the installers to follow these instructions .
We would like to thank Nasreddine Bencherchali who discovered the issues and responsibly disclosed them to Kaspersky.
Advisory issued on August 5, 2022
Kaspersky has fixed the security issue (CVE-2022-27535) in Kaspersky Secure Connection. An authenticated attacker could trigger arbitrary file deletion in the system. Before doing this, an attacker had to create a specific file link and convince the user to run "Delete All Service Data And Reports" feature.
List of affected products
Kaspersky VPN Secure Connection prior to 21.6
Kaspersky VPN Secure Connection 21.6
We recommend our users to check their current application version and install the latest version.
We would like to thank researcher Zeeshan Shaikh from Synopsys who discovered this issue and responsibly disclosed it.
Advisory issued on March 31, 2022
Kaspersky has fixed a security issue CVE-2021-27223 in one of its modules, which was incorporated in Kaspersky Anti-Virus products for and Kaspersky Endpoint Security. An authenticated attacker with user rights could cause Windows crash by running a specially crafted application.
List of affected products
Kaspersky Internet Security
Kaspersky Total Security
Kaspersky Small Office Security
Kaspersky Security Cloud
Kaspersky Endpoint Security
The products mentioned above with antivirus databases released in June 2021 and later.
The fix was delivered to users automatically. To make sure that the fix is installed, a user can check that the antivirus databases are up to date. Our applications support automatic updating procedure to make the process of receiving updates easier.
We would like to thank the following researchers who discovered this issue and responsibly disclosed it: Straghkov Denis, Kurmangaleev Shamil, Fedotov Andrey, Kuts Daniil, Mishechkin Maxim, Akolzin Vitaliy of Institute for System Programming of the Russian Academy of Sciences (ISPRAS). The security issue was discovered using the dynamic analysis tool Crusher (made by ispras.ru).
Advisory issued on March 31, 2022
Kaspersky has fixed a security issue CVE-2022-27534 that was located in a data parsing module and potentially allowed an attacker with ordinary user privileges to execute arbitrary code. Issue type: Arbitrary Code Execution.
List of affected products
Kaspersky Anti-Virus with antivirus databases released before 12.03.2022
Kaspersky Internet Security with antivirus databases released before 12.03.2022
Kaspersky Total Security with antivirus databases released before 12.03.2022
Kaspersky Small Office Security with antivirus databases released before 12.03.2022
Kaspersky Security Cloud with antivirus databases released before 12.03.2022
Kaspersky Endpoint Security with antivirus databases released before 12.03.2022
Kaspersky Anti-Virus with antivirus databases released after 12.03.2022
Kaspersky Internet Security with antivirus databases released after 12.03.2022
Kaspersky Total Security with antivirus databases released after 12.03.2022
Kaspersky Small Office Security with antivirus databases released after 12.03.2022
Kaspersky Security Cloud with antivirus databases released after 12.03.2022
Kaspersky Endpoint Security with antivirus databases released after 12.03.2022
The fix was delivered to users automatically. To make sure that the fix is installed, a user can check that the antivirus databases are up to date. Our applications support automatic updating procedure to make the process of receiving updates easier.
We would like to thank researcher Georgy Zaytsev of Positive Technologies who discovered the issue and responsibly disclosed it.
Advisory issued on November 22, 2021
Kaspersky has fixed the following security problems in consumer products for Windows:
[1] The installer of Kaspersky VPN Secure Connection was vulnerable to arbitrary file deletion. It could allow an attacker to delete any file during the installation procedure.
[2] The installers of Kaspersky Anti-Virus products family were vulnerable to loading of a specially crafted XML file during the installation procedure.
[3] A component in Kaspersky Password Manager could allow an attacker to elevate a process Integrity level from Medium to High (CVE-2021-35052).
[4] An attacker could disable the Safe Money component of the company’s AV products by abusing Windows symbolic links (CVE-2022-27533).
List of affected products
Kaspersky VPN Secure Connection prior to 21.3 [1]
Kaspersky Anti-Virus prior to 21.3 [2]
Kaspersky Internet Security prior to 21.3 [1, 2]
Kaspersky Total Security prior to 21.3 [1, 2]
Kaspersky Small Office Security prior to 21.3 [2]
Kaspersky Security Cloud prior to 21.3 [1, 2]
Kaspersky Password Manager prior to 9.0.2 Patch R [3]
All versions of Kaspersky AV products for (Kaspersky Security Cloud, Kaspersky Internet Security, Kaspersky Total Security) are affected by the issue [4]
Kaspersky VPN Secure Connection 21.3 [1]
Kaspersky Anti-Virus 21.3 [2]
Kaspersky Internet Security 21.3 [1, 2]
Kaspersky Total Security 21.3 [1, 2]
Kaspersky Small Office Security 21.3 [2]
Kaspersky Security Cloud 21.3 [1, 2]
Kaspersky Password Manager 9.0.2 Patch R [3]
All versions of Kaspersky AV products for (Kaspersky Security Cloud, Kaspersky Internet Security, Kaspersky Total Security) with antivirus databases released in November 2021 and later [4]
We recommend our users to check the application version and install the latest updates. Our products support automatic updating procedure to make the process of receiving updates easier.
We would like to thank the following researchers who discovered the issues and responsibly disclosed them:
Mohammed Shameem Shahnawaz who discovered issues 1, 2 and reported them to us.
Abdelhamid Naceri working with Trend Micro Zero Day Initiative who discovered issues 3, 4 and reported them to us.
Phishing advisory issued on November 1, 2021
Phishing emails seemingly coming from a Kaspersky email address
Kaspersky security experts have recently seen a huge uptick in spearphishing emails designed to steal Office 365 credentials. These phishing attempts rely on a phishing kit we named “Iamtheboss” used in conjunction with another phishing kit known as “MIRCBOOT”. The activity may be associated with multiple cybercriminals. The phishing e-mails are usually arriving in the form of “Fax notifications” and lure users to fake websites collecting credentials for Microsoft online services. These emails have various sender addresses, including but not limited to [email protected]. They are sent from multiple websites including Amazon Web Services infrastructure.
The example of the email is below:
We encourage users to execute caution and be vigilant even if the email seems to come from a familiar brand or email address. The detailed how-to on checking email headers to ensure senders’ identity is posted on the Kaspersky blog .
During the investigation of this phishing activity, Kaspersky experts determined that some e-mails were sent using Amazon’s Simple Email Service (SES) and legitimate SES token. This access token was issued to a third party contractor during the testing of the website 2050.earth. The site is also hosted in Amazon infrastructure. Upon discovery of these phishing attacks, the SES token was immediately revoked. No server compromise, unauthorized database access or any other malicious activity was found at 2050.earth and associated services.
Advisory issued on November 1, 2021
Possible system denial of service in case of arbitrary changing Firefox browser parameters. An attacker could change specific Firefox browser parameters file in a certain way and then reboot the system to make the system unbootable (CVE-2021-35053).
List of affected applications
Kaspersky Anti-Virus prior to 21.3.10.391(g)
Kaspersky Internet Security prior to 21.3.10.391(g)
Kaspersky Total Security prior to 21.3.10.391(g)
Kaspersky Small Office Security prior to 21.3.10.391(g)
Kaspersky Security Cloud prior to 21.3.10.391(g)
Kaspersky Endpoint Security versions from 11.1 to 11.6 (inclusively)
Kaspersky Anti-Virus 21.3.10.391(g)
Kaspersky Internet Security 21.3.10.391(g)
Kaspersky Total Security 21.3.10.391(g)
Kaspersky Small Office Security 21.3.10.391(g)
Kaspersky Security Cloud 21.3.10.391(g)
Kaspersky Endpoint Security 11.7
We recommend our users to check the application version and install the latest updates. Our applications for support automatic updating procedure to make the process of receiving updates easier.
For Kaspersky Endpoint Security users who are unable to update the product, we can recommend following to mitigate this issue:
Use Mozilla certificate store instead of Windows certificate store (default value) for scanning secure connections in Mozilla Firefox. To do this, enable the usage of Mozilla certificate store in local interface of the application and add Kaspersky certificate in Mozilla certificate store. Please Kaspersky technical support for the instruction on how to centrally change application settings for all computers of the company.
We would like to thank researcher Abdelhamid Naceri working with Trend Micro Zero Day Initiative who discovered the issue and responsibly disclosed it.
Advisory issued on April 27, 2021
Kaspersky has fixed a security issue in Kaspersky Password Manager product for several platforms (CVE-2020-27020). Password generator was not completely cryptographically strong and potentially allowed an attacker to predict generated passwords in some cases. An attacker would need to know some additional information (for example, time of password generation).
All public versions of Kaspersky Password Manager liable to this issue now have a new logic of password generation and a passwords update alert for cases when a generated password is probably not strong enough.
List of affected applications
Kaspersky Password Manager for Windows prior to 9.0.2 Patch F
Kaspersky Password Manager for Android prior to 9.2.14.872
Kaspersky Password Manager for iOS prior to 9.2.14.31
Kaspersky Password Manager for Windows 9.0.2 Patch F
Kaspersky Password Manager for Android 9.2.14.872
Kaspersky Password Manager for iOS 9.2.14.31
We recommend our users to check the application version and install the latest updates. To make the process of receiving updates easier, our products support automatic updates.
We would like to thank researcher jibee who discovered the issue and responsibly disclosed it to us.
Advisory issued on March 31, 2021
Kaspersky has fixed the following security problems:
Kaspersky Anti-Virus prior to 20 Patch L
Kaspersky Internet Security prior to 20 Patch L
Kaspersky Total Security prior to 20 Patch L
Kaspersky Small Office Security prior to 20 Patch L
Kaspersky Security Cloud prior to 20 Patch L
Kaspersky Anti-Virus 20 Patch L
Kaspersky Internet Security 20 Patch L
Kaspersky Total Security 20 Patch L
Kaspersky Small Office Security 20 Patch L
Kaspersky Security Cloud 20 Patch L
Kaspersky Anti-Virus from 21.1 and prior to 21.2
Kaspersky Internet Security from 21.1 and prior to 21.2
Kaspersky Total Security from 21.1 and prior to 21.2
Kaspersky Small Office Security from 21.1 and prior to 21.2
Kaspersky Security Cloud from 21.1 and prior to 21.2
Kaspersky Anti-Virus 21.2
Kaspersky Internet Security 21.2
Kaspersky Total Security 2021 21.2
Kaspersky Small Office Security 21.2
Kaspersky Security Cloud 21.2
Kaspersky Anti-Virus prior to 21.3
Kaspersky Internet Security prior to 21.3
Kaspersky Total Security prior to 21.3
Kaspersky Small Office Security prior to 21.3
Kaspersky Security Cloud prior to 21.3
Kaspersky Anti-Virus 21.3
Kaspersky Internet Security 21.3
Kaspersky Total Security 2021 21.3
Kaspersky Small Office Security 21.3
Kaspersky Security Cloud 21.3
Kaspersky Anti-Virus prior to 21.3
Kaspersky Internet Security prior to 21.3
Kaspersky Total Security prior to 21.3
Kaspersky Small Office Security prior to 21.3
Kaspersky Security Cloud prior to 21.3
Kaspersky Anti-Virus 21.3
Kaspersky Internet Security 21.3
Kaspersky Total Security 21.3
Kaspersky Small Office Security 21.3
Kaspersky Security Cloud 21.3
Kaspersky Internet Security for Mac prior to 21.1
Kaspersky Internet Security for Mac 21.1
We recommend our users to check the application version and install the latest updates. Our products support automatic updating procedure to make the process of receiving updates easier. To apply these updates a computer reboot may be required. To update a solution for business, please our technical support to clarify the details.
We would like to thank the following researchers who discovered the issues and responsibly disclosed them:
Kim Dong-Hyeon (abbadeed) who discovered issues 1, 2 and reported them to us.
Abdelhamid Naceri (halove23) who discovered issues 3, 4 and reported them to us.
Csaba Fitzl (theevilbit) who discovered issue 5 and reported it to us.
Advisory issued on March 30, 2021
Kaspersky has fixed the following security issues in consumer and corporate products for Windows that were publicly disclosed earlier.
[1] The web protection component was vulnerable to arbitrary file corruption due to insufficient check of file paths on reparse points. Using this flaw, an authenticated attacker could abuse our component to corrupt arbitrary files in the system without any interaction with the user. Issue type: LPE.
[2] The Safe Money component that provides secure online operations was vulnerable to arbitrary code execution with high privileges. To exploit this issue an authenticated attacker needed to interact with the user. Issue type: LPE.
List of affected products
Kaspersky Anti-Virus version 21.2 and earlier [1]
Kaspersky Internet Security version 21.2 and earlier [1, 2]
Kaspersky Total Security version 21.2 and earlier [1, 2]
Kaspersky Security Cloud version 21.2 and earlier [1, 2]
Kaspersky Small Office Security version 21.2 and earlier [1, 2]
Kaspersky Endpoint Security for Windows 11.5.0 and earlier [1]
Kaspersky Anti-Virus version 21.3 [1]
Kaspersky Internet Security version 21.3 [1, 2]
Kaspersky Total Security version 21.3 [1, 2]
Kaspersky Security Cloud version 21.3 [1, 2]
Kaspersky Small Office Security version 21.3 [1, 2]
Kaspersky Endpoint Security for Windows version 11.6.0 [1]
We recommend our users to check the application version and install the latest updates. Our products support automatic updating procedure to make the process of receiving updates easier. To apply these updates a computer reboot may be required. To update a solution for business, please our technical support to clarify the details.
Our anti-malware detection rules for the products were updated and delivered to users once we got information the issues. This allowed us to block attempts of exploiting the vulnerability before the updates became available (PDM:Exploit.Win32.Generic.nblk).
Advisory issued on 17th February, 2021
Kaspersky has fixed a security issue in consumer and corporate products that was publicly disclosed earlier (CVE-2020-26200). A component of our boot loader allowed loading of untrusted UEFI modules due to insufficient check of their authenticity. This component is incorporated in Kaspersky Rescue Disk (KRD) and was trusted by the Authentication Agent of Full Disk Encryption in Kaspersky Endpoint Security (KES). This issue allowed to bypass the UEFI Secure Boot security feature. An attacker would need physical access to the computer to exploit it. Otherwise, local administrator privileges would be required to modify the boot loader component.
List of affected products
Kaspersky Rescue Disk prior to 18.0.11.3 (patch C)
Kaspersky Endpoint Security 10 SP2 MR2 with the Full Disk Encryption component installed
Kaspersky Endpoint Security 10 SP2 MR3 with the Full Disk Encryption component installed
Kaspersky Endpoint Security 11.0.0 with the Full Disk Encryption component installed
Kaspersky Endpoint Security 11.0.1 with the Full Disk Encryption component installed
Kaspersky Endpoint Security 11.1.0 with the Full Disk Encryption component installed
Kaspersky Rescue Disk 18.0.11.3 (patch C)
Kaspersky Endpoint Security 10 SP2 MR4
Kaspersky Endpoint Security 11.0 Security Fix 1
Kaspersky Endpoint Security 11.1.1 and later
We recommend our users to check the application version and install the latest updates if not installed. After installing a new version of our product, we recommend to install a Microsoft security update 4535680 . A computer reboot may be required for applying updates.
To update a solution for business, please our technical support using Company Account.
Advisory issued on 15th December, 2020
Kaspersky has fixed the following security problems in products for Windows:
Issue 1: Due to unsafe DLL path, the installer of Kaspersky Anti-Ransomware Tool (KART) was vulnerable to a DLL hijacking attack that allowed an attacker to elevate privileges in the system. Issue type: LPE.
Issue 2: One of AV engine's components was vulnerable to a path traversal attack thus allowing an attacker to create files in privileged file locations. Issue type: LPE.
Issue 3: In minor scenarios, Kaspersky Password Manager could run a browser with High integrity level. Issue type: LPE.
Issue 4: Unused Data Cleaner component in Kaspersky Total Security has been improved against attacks based on the abuse of symbolic links. Issue type: LPE.
Issue 5: File Shredder component in Kaspersky Total Security that provides secure file deletion was vulnerable to a race condition attack when checking a file path for reparse points. Using this flaw, an attacker could use this component to delete arbitrary files in the system. Issue type: LPE.
List of affected products
Kaspersky Anti-Ransomware Tool prior to version 5.0 patch E (issue 1)
Kaspersky Password Manager prior to version 9.2 patch L (issue 3)
Kaspersky Total Security prior to version 2021 (issue 4)
Kaspersky Security Cloud prior to version 2021 (issue 4)
Kaspersky Total Security prior to version 2021 MR2 (issue 5)
Kaspersky Security Cloud prior to version 2021 MR2 (issue 5)
Kaspersky Anti-Ransomware Tool 5.0 patch E (issue 1)
Kaspersky Password Manager 9.2 patch L (issue 3)
Kaspersky Total Security 2021 (issue 4)
Kaspersky Security Cloud 2021 (issue 4)
Kaspersky Total Security 2021 MR2 (issue 5)
Kaspersky Security Cloud 2021 MR2 (issue 5)
To fix the issue 2, update antivirus databases to the latest version or wait for the automatic update.
We recommend our users to check the application version and install the latest updates. Our products support automatic updating procedure to make the process of receiving updates easier. To apply these updates a computer reboot may be required. To update a solution for business, please our technical support to clarify the details.
We would like to thank the following researchers who discovered the issues and responsibly disclosed them:
Eran Shimony of CyberArk Labs who discovered issue 1 and reported it to us.
houjingyi who discovered issue 2 and reported it to us.
Abdelhamid Naceri who discovered issues 3, 4, 5 and reported it to us.
Advisory issued on 29th July, 2020
Kaspersky has fixed the following security problems in products for Windows:
The installer of Kaspersky VPN Secure Connection was vulnerable to arbitrary file deletion that could allow an attacker to delete any file in the system (CVE-2020-25043). Issue type: DoS.
Kaspersky Virus Removal Tool (KVRT) was vulnerable to arbitrary file corruption that could provide an attacker with the opportunity to eliminate content of any file in the system (CVE-2020-25044). Issue type: DoS.
Due to unsafe DLL path, the installer of Kaspersky Security Center was susceptible to a DLL hijacking attack that allowed an attacker to elevate privileges in the system (CVE-2020-25045). Issue type: LPE.
Due to unsafe DLL path, the installer of Kaspersky Security Center Web Console was vulnerable to a DLL hijacking attack that allowed an attacker to elevate privileges in the system (CVE-2020-25045). Issue type: LPE.
Due to unsafe DLL path, the installer of Kaspersky Anti-Ransomware Tool (KART) was vulnerable to a DLL hijacking attack that allowed an attacker to elevate privileges in the system (CVE-2020-28950). Issue type: LPE.
The above issues are classified as local attacks. It means that an attacker should be authenticated in the system at the time of attack. Cases 1, 3, 4, 5 can be exploited only during the installation of a product. We have not registered any attempts to exploit these vulnerabilities in the wild.
List of affected products
Kaspersky VPN Secure Connection prior to 5.0
Kaspersky Virus Removal Tool prior to 15.0.23.0
Kaspersky Security Center prior to 12
Kaspersky Security Center Web Console prior to 12 Patch A
Kaspersky Anti-Ransomware Tool prior to KART 4.0 Patch C
Kaspersky VPN Secure Connection 5.0
Kaspersky Virus Removal Tool 15.0.23.0
Kaspersky Security Center 12
Kaspersky Security Center Web Console 12 Patch A
Kaspersky Anti-Ransomware Tool 4.0 Patch C
We recommend our users to check the application version and install the latest updates. To make the process of receiving updates easier, our products support automatic updates. A computer reboot may be required for applying updates. To update a solution for business, please our technical support for details.
We would like to thank the following researchers who discovered the issues and responsibly disclosed them:
Eran Shimony of CyberArk Labs who discovered issues 1, 2, 3, and 4 and reported it to us.
Shahee Mirza of BEETLES who discovered issue 5 and reported it to us.
Advisory issued on 15th May, 2020
Kaspersky has fixed a security issue in its consumer and corporate products that was publicly disclosed earlier. Fixed versions of the products were released several months ago. The vulnerability allowed abuse of products' AV scanning feature for arbitrary file deletion. The exploitation of this issue was possible in a local attack scenario and required from an attacker to be authenticated in the system to run a specially crafted application.
List of affected products
Consumer products for Windows:
Kaspersky Anti-Virus prior to 2019
Kaspersky Internet Security prior to 2019
Kaspersky Total Security prior to 2019
Kaspersky Free prior to 2019
Kaspersky Security Cloud prior to 2019
Corporate products for Windows:
Kaspersky Small Office Security prior to 6
Kaspersky Endpoint Security prior to 11.1
Consumer products for macOS:
Kaspersky Internet Security prior to 2020 Patch A
Corporate products for Linux:
Kaspersky Endpoint Security prior to version 10 SP1 MR1
Consumer products for Windows:
Kaspersky Anti-Virus 2019 and later
Kaspersky Internet Security 2019 and later
Kaspersky Total Security 2019 and later
Kaspersky Free 2019 and later
Kaspersky Security Cloud 2019 and later
Corporate products for Windows:
Kaspersky Small Office Security 6 and later
Kaspersky Endpoint Security 11.1 and later
Consumer products for macOS:
Kaspersky Internet Security 2020 Patch A and later
Corporate products for Linux:
Kaspersky Endpoint Security 10 SP1 MR1 and later
We recommend our users to check the application version and install the latest updates. Our products support automatic updating procedure to make the process of receiving updates easier. To apply these updates a computer reboot may be required. To update a solution for business, please our technical support to clarify the details.
We would like to thank company RACK911 Labs who discovered the issue and reported it to us.
Advisory issued on 26th February, 2020
Kaspersky has fixed a security issue in consumer and corporate products that was publicly disclosed earlier. A component responsible for interprocess communications was vulnerable to arbitrary code execution due to weak check of incoming data in some specific cases. Depending on the product, this could allow an attacker to elevate privileges in the OS, provided that the vulnerable component works within the context of process with high privileges. At the moment of exploitation an attacker must be already authenticated in the system (local attack). In case of such products as consumer Kaspersky Anti-Virus products family and Endpoint Security, an attacker also needs to bypass product's self-defense to perform exploitation.
We have not registered any attempts to exploit this vulnerability in the wild.
List of affected products
Consumer products for Windows:
Kaspersky Anti-Virus prior to 2019 Patch H, 2020 Patch D.
Kaspersky Internet Security prior to 2019 Patch H, 2020 Patch D.
Kaspersky Total Security prior to 2019 Patch H, 2020 Patch D.
Kaspersky Free prior to 2019 Patch H, 2020 Patch D.
Kaspersky Security Cloud prior to 2019 Patch H, 2020 Patch D.
Kaspersky Password Manager prior to 9.2 Patch C.
Kaspersky Safe Kids prior to 1.5 Patch C.
Kaspersky Software Updater prior to 2.1 Patch A.
Corporate products for Windows:
Kaspersky Endpoint Security 10 SP2 without pf3223.
Kaspersky Endpoint Security 10 SP2 MR3 without pf3528.
Kaspersky Endpoint Security 11.0.0 without pf5145.
Kaspersky Endpoint Security 11.0.1 without pf5352.
Kaspersky Endpoint Security 11.1 without pf7063.
Kaspersky Endpoint Security 11.1.1 without pf7523.
Kaspersky Small Office Security prior to 6 Patch H, 7 Patch D.
Kaspersky Anti Targeted Attack Agent prior to 3.6.1.
Consumer products for Windows:
Kaspersky Anti-Virus 2019 Patch H, 2020 Patch D and later.
Kaspersky Internet Security 2019 Patch H, 2020 Patch D and later.
Kaspersky Total Security 2019 Patch H, 2020 Patch D and later.
Kaspersky Free 2019 Patch H, 2020 Patch D and later.
Kaspersky Security Cloud 2019 Patch H, 2020 Patch D and later.
Kaspersky Password Manager 9.2 Patch C and later.
Kaspersky Safe Kids 1.5 Patch C and later.
Kaspersky Software Updater 2.1 Patch A and later.
Corporate products for Windows:
Kaspersky Endpoint Security 10 SP2 with pf3223.
Kaspersky Endpoint Security 10 SP2 MR3 with pf3528.
Kaspersky Endpoint Security 11.0.0 with pf5145.
Kaspersky Endpoint Security 11.0.1 with pf5352.
Kaspersky Endpoint Security 11.1 with pf7063.
Kaspersky Endpoint Security 11.1.1 with pf7523.
Kaspersky Small Office Security 6 Patch H, 7 Patch D and later.
Kaspersky Anti Targeted Attack Agent 3.6.1.
We recommend users to check product version and install updates. Our products support automatic updating procedure to make process of receiving updates easier. To apply these updates a reboot may be required. To update a solution for business, please out technical support via Kaspersky CompanyAccount to receive a patch.
Our anti-malware detection rules for the products were updated and delivered to users once we got information the issue. This allowed us to block attempts of exploiting the vulnerability before the updates became available (PDM:Exploit.Win32.Virsli.a).
Advisory issued on 2nd December, 2019
Kaspersky has fixed a security issue CVE-2019-15689 found in Kaspersky Secure Connection 4.0 (2020). One of the product executable files was susceptible to a DLL hijacking attack that could potentially allow third-parties to locally execute arbitrary code in its process context. The severity of the issue was assessed as low, because an attacker must have administrator privileges to drop malicious DLL file into the product's folder. No privilege escalation. Issue category: DLL hijacking. Issue type: Arbitrary Code Execution.
We also have fixed three bugs in one of anti-virus (AV) engine components that is responsible for work with ZIP archives. The fix for this component corrects its behaviour in situation of antivirus scanning specially crafted ZIP archives. These malformed archives could be used to circumvent our antivirus scan process. The bugs affected Kaspersky products with antivirus databases.
List of affected products
The issue affected Secure Connection product and consumer products in those it is incorporated:
Kaspersky Secure Connection prior to version 4.0 (2020) patch E.
Kaspersky Internet Security prior to version 2020 patch E.
Kaspersky Total Security prior to version 2020 patch E.
Kaspersky Security Cloud prior to version 2020 patch E.
Kaspersky Secure Connection 4.0 (2020) patch E.
Kaspersky Internet Security 2020 patch E.
Kaspersky Total Security 2020 patch E.
Kaspersky Security Cloud 2020 patch E.
We recommend users to install these updates. Our products have automatic updating procedure to make process of receiving updates easier. To apply these updates, the product restart is required. Also to eliminate mentioned bugs in antivirus engine it is necessary to update antivirus bases to the latest version, which is performed automatically during auto-updating procedure.
We would like to thank the following researchers who discovered the issues and responsibly disclosed them:
Peleg Hadar from SafeBreach for reporting DLL hijacking in Secure Connection.
Thierry Zoller for reporting bugs in antivirus engine.
Advisory issued on 25th November, 2019
Kaspersky Lab has fixed a security issue found by Wladimir Palant in Kaspersky Password Manager that could potentially lead remote unauthorized access by 3rd parties to information address items which are stored in the vault while it is in unlocked state. No other data in the vault could be compromised. Issue category: Data Leakage. Issue type: Information Disclosure.
To exploit this issue an attacker would need to lure a user for visiting a specially crafted web page.
List of affected products
Kaspersky Password Manager for Windows 9.1.
Kaspersky Password Manager for Windows 9.2.
We recommend our users to migrate to new version of the product.
We would like to thank researcher Wladimir Palant who discovered the issue and reported it to us.
Advisory issued on 25th November, 2019
Kaspersky has fixed the following security problems in Anti-Virus products family for Windows:
[1] Kaspersky Protection extension for web brow...
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
