Code Injection in Kaspersky Lab products - CVE-2022-27534

 

Code Injection in Kaspersky Lab products - CVE-2022-27534

Published: April 29, 2022


Vulnerability identifier: #VU62699
CSH Severity: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2022-27534
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Kaspersky Anti-Virus
Kaspersky Internet Security
Total Security
Small Office Security
Security Cloud
Endpoint Security for Windows
Software vendor:
Kaspersky Lab

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper input validation in a data parsing module. A remote user can send a specially crafted request and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Remediation

Install updates from vendor's website.

External links