First published: Fri Apr 01 2022(Updated: )
A denial-of-service issue existed in one of modules that was incorporated in Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security. A local user could cause Windows crash by running a specially crafted binary module. The fix was delivered automatically. Credits: (Straghkov Denis, Kurmangaleev Shamil, Fedotov Andrey, Kuts Daniil, Mishechkin Maxim, Akolzin Vitaliy) @ ISPRAS
Credit: vulnerability@kaspersky.com
Affected Software | Affected Version | How to fix |
---|---|---|
Kaspersky Anti-Virus | <2021-06 | |
Kaspersky Endpoint Security | <2021-06 | |
Kaspersky Internet Security | <2021-06 | |
Kaspersky Security Cloud | <2021-06 | |
Kaspersky Small Office Security | <2021-06 | |
Kaspersky Total Security | <2021-06 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-27223 is medium, with a severity value of 5.5.
Kaspersky Anti-Virus, Kaspersky Endpoint Security, Kaspersky Internet Security, Kaspersky Security Cloud, Kaspersky Small Office Security, and Kaspersky Total Security are affected by CVE-2021-27223.
CVE-2021-27223 can be exploited by a local user running a specially crafted binary module, which can cause a Windows crash.
Yes, a fix for CVE-2021-27223 was delivered automatically.
You can find more information about CVE-2021-27223 on the Kaspersky support website: [link](https://support.kaspersky.com/general/vulnerability.aspx?el=12430#310322_1)