CVE-2022-27534

EUVD-2022-32035
Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security with antivirus databases released before 12 March 2022 had a bug in a data parsing module that potentially allowed an attacker to execute arbitrary code. The fix was delivered automatically. Credits: Georgy Zaytsev (Positive Technologies).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 69%
Affected Products (NVD)
VendorProductVersion
kasperskyanti-virus
𝑥
< 12.03.2022
kasperskyendpoint_security
𝑥
< 12.03.2022
kasperskyinternet_security
𝑥
< 12.03.2022
kasperskysecurity_cloud
𝑥
< 12.03.2022
kasperskysmall_office_security
𝑥
< 12.03.2022
kasperskytotal_security
𝑥
< 12.03.2022
𝑥
= Vulnerable software versions