Missing Encryption of Sensitive Data in Kaspersky Internet Security - CVE-2017-12817
Published: August 25, 2017 / Updated: August 8, 2020
Vulnerability identifier: #VU38422
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-12817
CWE-ID: CWE-311
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
In Kaspersky Internet Security for Android 11.12.4.1622, some of the application trace files were not encrypted.
Affected software
Kaspersky Internet Security
How to mitigate CVE-2017-12817
Install update from vendor's website.