SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-15687

Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component was vulnerable to remote disclosure of various…

MEDIUM 6.5EPSS 1.62%

Does this matter?

Lower severity and a low EPSS score (1.62%). Track it; it rarely justifies an emergency change on its own.

Description

Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component was vulnerable to remote disclosure of various information about the user's system (like Windows version and version of the product, host unique ID). Information Disclosure.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS
1.62% probability · 75th percentile
CISA KEV
Not listed
Affected
kaspersky/anti-virus · kaspersky/internet security · kaspersky/security cloud · kaspersky/small office security · kaspersky/total security
Source
vulnerability@kaspersky.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.