Kaspersky Security Update – 5 August 2022

Kaspersky has released a security update to address a high vulnerability that affects Kaspersky’s VPN secure connection. The attacker could exploit this vulnerability to take control of the affected systems.

Kaspersky’s VPN secure connection 21.3.10.391(h) is vulnerable to a high-severity local privilege-escalation (LPE) vulnerability which would allow the attacker to gain administrative privileges and take full control over a victim’s computer.

Kaspersky VPN local privilege-escalation (CVE-2022-27535):

  • CVSS: 7.8
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Privilege Escalation
  • Remediation Level: Official Fix
Vulnerabilities

CVE-2022-27535

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

List of Advisories (Kaspersky.com)

References