First published: Thu Jul 18 2019(Updated: )
Information Disclosure in Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security versions up to 2019 could potentially disclose unique Product ID by forcing victim to visit a specially crafted webpage (for example, via clicking phishing link). Vulnerability has CVSS v3.0 base score 2.6
Credit: vulnerability@kaspersky.com
Affected Software | Affected Version | How to fix |
---|---|---|
Kaspersky Anti-Virus | <=2019 | |
Kaspersky Free Anti-virus | <=2019 | |
Kaspersky Internet Security | <=2019 | |
Kaspersky Small Office Security | <=6.0 | |
Kaspersky Total Security | <=2019 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2019-8286.
The severity of CVE-2019-8286 is medium with a CVSS v3.0 base score of 4.3.
Versions up to 2019 of Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Free Anti-virus, Kaspersky Small Office Security, and Kaspersky Total Security are affected by CVE-2019-8286.
CVE-2019-8286 can be exploited by forcing the victim to visit a specially crafted webpage, such as through a phishing link.
Yes, Kaspersky has released a security update to address this vulnerability. It is recommended to update to the latest version of the affected software.