First published: Fri Aug 05 2022(Updated: )
Kaspersky VPN Secure Connection for Windows version up to 21.5 was vulnerable to arbitrary file deletion via abuse of its 'Delete All Service Data And Reports' feature by the local authenticated attacker.
Credit: vulnerability@kaspersky.com
Affected Software | Affected Version | How to fix |
---|---|---|
Kaspersky VPN Secure Connection | <21.6 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27535 has been classified as a medium severity vulnerability.
To fix CVE-2022-27535, update Kaspersky VPN Secure Connection to version 21.6 or later.
CVE-2022-27535 affects Kaspersky VPN Secure Connection users running versions up to 21.5.
CVE-2022-27535 is an arbitrary file deletion vulnerability exploitable by local authenticated attackers.
Yes, you can check your version of Kaspersky VPN Secure Connection to determine if it is prior to version 21.6.