CVE-2022-27534

Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security with antivirus databases released before 12 March 2022 had a bug in a data parsing module that potentially allowed an attacker to execute arbitrary code. The fix was delivered automatically. Credits: Georgy Zaytsev (Positive Technologies).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KasperskyCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 69%
VendorProductVersion
kasperskyanti-virus
𝑥
< 12.03.2022
kasperskyendpoint_security
𝑥
< 12.03.2022
kasperskyinternet_security
𝑥
< 12.03.2022
kasperskysecurity_cloud
𝑥
< 12.03.2022
kasperskysmall_office_security
𝑥
< 12.03.2022
kasperskytotal_security
𝑥
< 12.03.2022
𝑥
= Vulnerable software versions