CVE-2021-35053: Kaspersky Total Security Link Following Denial-of-Service Vulnerability
Possible system denial of service in case of arbitrary changing Firefox browser parameters. An attacker could change specific Firefox browser parameters file in a certain way and then reboot the system to make the system unbootable.
Other sources
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Kaspersky Total Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within Kaspersky Lab Launcher. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
— ZDI
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Kaspersky Total Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Safe Browser. By creating a symbolic link, an attacker can abuse the service to overwrite a file. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-35053?
CVE-2021-35053 is a vulnerability in Kaspersky Total Security that allows local attackers to create a denial-of-service condition.
How does CVE-2021-35053 affect Kaspersky Total Security?
CVE-2021-35053 affects Kaspersky Total Security by allowing local attackers to create a denial-of-service condition.
What is the severity of CVE-2021-35053?
CVE-2021-35053 has a severity rating of 7.5 (high).
How can CVE-2021-35053 be exploited?
CVE-2021-35053 can be exploited by executing low-privileged code on the target system.
Is there a fix for CVE-2021-35053?
Yes, please refer to the official Kaspersky support page for information on how to fix CVE-2021-35053.