First published: Wed Sep 02 2020(Updated: )
Installers of Kaspersky Security Center and Kaspersky Security Center Web Console prior to 12 & prior to 12 Patch A were vulnerable to a DLL hijacking attack that allowed an attacker to elevate privileges in the system.
Credit: vulnerability@kaspersky.com
Affected Software | Affected Version | How to fix |
---|---|---|
Kaspersky Security Center | <12 | |
Kaspersky Security Center Web Console | <12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25045 is classified as a high severity vulnerability due to the potential for privilege escalation.
To mitigate CVE-2020-25045, update Kaspersky Security Center and Kaspersky Security Center Web Console to version 12 Patch A or later.
CVE-2020-25045 allows attackers to execute unauthorized code with elevated privileges on affected systems.
Kaspersky Security Center and Kaspersky Security Center Web Console versions prior to 12 and 12 Patch A are vulnerable to CVE-2020-25045.
Currently, there are no known workarounds for CVE-2020-25045, so updating is the best course of action.