First published: Tue Nov 26 2019(Updated: )
Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component allowed an attacker remotely disable various anti-virus protection features. DoS, Bypass.
Credit: vulnerability@kaspersky.com
Affected Software | Affected Version | How to fix |
---|---|---|
Kaspersky Anti-Virus | <=2020 | |
Kaspersky Anti-Virus | <=2020 | |
Kaspersky Internet Security | <=2020 | |
Kaspersky Security Cloud | <=2020 | |
Kaspersky Small Office Security | <=7 | |
Kaspersky Total Security | <=2020 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15686 is a vulnerability in Kaspersky products that allows an attacker to remotely disable various anti-virus protection features, leading to denial-of-service (DoS) and bypass.
Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, and Kaspersky Security Cloud up to 2020 are affected by CVE-2019-15686.
The severity of CVE-2019-15686 is medium with a CVSS score of 4.3.
An attacker can exploit CVE-2019-15686 to remotely disable various anti-virus protection features in affected Kaspersky products.
Yes, Kaspersky has released a fix for CVE-2019-15686. It is recommended to update to the latest version of the affected products to mitigate the vulnerability.