Input validation error in Kaspersky Lab products - CVE-2021-27223
Published: April 29, 2022
Vulnerability identifier: #VU62698
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-27223
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A local user can run a specially crafted application and perform a denial of service (DoS) attack.
Affected software
Kaspersky Anti-Virus
Kaspersky Internet Security
Total Security
Small Office Security
Security Cloud
Endpoint Security for Windows
Kaspersky Internet Security
Total Security
Small Office Security
Security Cloud
Endpoint Security for Windows
How to mitigate CVE-2021-27223
Install updates from vendor's website.
Kaspersky Anti-Virus - update to 21.3.10.391(c)
Kaspersky Internet Security - update to 21.3.10.391(c)
Total Security - update to 21.3.10.391(c)
Small Office Security - update to 21.3.10.391(c)
Security Cloud - update to 21.3.10.391(c)
Endpoint Security for Windows - update to 21.3.10.391(c)
Kaspersky Internet Security - update to 21.3.10.391(c)
Total Security - update to 21.3.10.391(c)
Small Office Security - update to 21.3.10.391(c)
Security Cloud - update to 21.3.10.391(c)
Endpoint Security for Windows - update to 21.3.10.391(c)