VulnerabilityModified
CVE-2022-27535
Kaspersky VPN Secure Connection for Windows version up to 21.5 was vulnerable to arbitrary file deletion via abuse of its 'Delete All Service Data And Reports' feature by the local authenticated attacker.
HIGH 7.8EPSS 0.32%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.32%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Kaspersky VPN Secure Connection for Windows version up to 21.5 was vulnerable to arbitrary file deletion via abuse of its 'Delete All Service Data And Reports' feature by the local authenticated attacker.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.32% probability · 25th percentile
- CISA KEV
- Not listed
- Affected
- kaspersky/vpn secure connection
- Source
- vulnerability@kaspersky.com
References
- https://forum.kaspersky.com/topic/kaspersky-statement-on-cve-2022-27535-26742/Vendor Advisory
- https://support.kaspersky.com/general/vulnerability.aspx?el=12430#050822Vendor Advisory
- https://www.synopsys.com/blogs/software-security/cyrc-advisory-kasperksy-vpn-microsoft-windows/Third Party Advisory
- https://forum.kaspersky.com/topic/kaspersky-statement-on-cve-2022-27535-26742/Vendor Advisory
- https://support.kaspersky.com/general/vulnerability.aspx?el=12430#050822Vendor Advisory
- https://www.synopsys.com/blogs/software-security/cyrc-advisory-kasperksy-vpn-microsoft-windows/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.