CVE-2022-27535: High severity kaspersky secure connection vulnerability
Published Aug 5, 2022
·Updated
Kaspersky VPN Secure Connection for Windows version up to 21.5 was vulnerable to arbitrary file deletion via abuse of its 'Delete All Service Data And Reports' feature by the local authenticated attacker.
Affected Software
2 affected components
Kaspersky VPN Secure Connection<21.6
Microsoft Windows
Event History
Aug 5, 2022
CVE Published
via MITRE·04:47 PM
Data Sourced
via MITRE·04:47 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-27535?
CVE-2022-27535 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2022-27535?
To fix CVE-2022-27535, update Kaspersky VPN Secure Connection to version 21.6 or later.
3
Who is affected by CVE-2022-27535?
CVE-2022-27535 affects Kaspersky VPN Secure Connection users running versions up to 21.5.
4
What type of vulnerability is CVE-2022-27535?
CVE-2022-27535 is an arbitrary file deletion vulnerability exploitable by local authenticated attackers.
5
Can I check if my Kaspersky VPN is vulnerable to CVE-2022-27535?
Yes, you can check your version of Kaspersky VPN Secure Connection to determine if it is prior to version 21.6.