CVE-2020-25043: High severity kaspersky secure connection vulnerability
Published Sep 2, 2020
·Updated
The installer of Kaspersky VPN Secure Connection prior to 5.0 was vulnerable to arbitrary file deletion that could allow an attacker to delete any file in the system.
Affected Software
1 affected component
Kaspersky VPN Secure Connection<5.0
Event History
Sep 2, 2020
CVE Published
via MITRE·07:28 PM
Data Sourced
via MITRE·07:28 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-25043?
CVE-2020-25043 is classified as a medium-severity vulnerability due to the potential for arbitrary file deletion.
2
How do I fix CVE-2020-25043?
The recommended fix for CVE-2020-25043 is to update Kaspersky VPN Secure Connection to version 5.0 or later.
3
What versions of Kaspersky VPN Secure Connection are affected by CVE-2020-25043?
Versions of Kaspersky VPN Secure Connection prior to 5.0 are affected by CVE-2020-25043.
4
What type of attack does CVE-2020-25043 facilitate?
CVE-2020-25043 facilitates an attack that allows arbitrary file deletion on the system.
5
Can CVE-2020-25043 be exploited remotely?
CVE-2020-25043 can potentially be exploited locally by an authenticated attacker to delete files.