CVE-2025-64984: XSS

Published Nov 20, 2025
·
Updated

Kaspersky has fixed a security issue in Kaspersky Endpoint Security for Linux (any version with anti-virus databases prior to 18.11.2025), Kaspersky Industrial CyberSecurity for Linux Nodes (any version with anti-virus databases prior to 18.11.2025), and Kaspersky Endpoint Security for Mac (12.0.0.325, 12.1.0.553, and 12.2.0.694 with anti-virus databases prior to 18.11.2025) that could have allowed a reflected XSS attack to be carried out by an attacker using phishing techniques.

Affected Software

3 affected components
Kaspersky Endpoint Security for Linux<18.11.2025
Kaspersky Industrial CyberSecurity for Linux Nodes<18.11.2025
Kaspersky Endpoint Security for Mac=12.0.0.325, =12.1.0.553, =12.2.0.694

Remediation

Information

Users should update anti-virus databases to use at least the version from 11/18/2025.

Information

Users of Kaspersky Endpoint Security for Mac versions 12.0.0.325 and 12.1.0.553 are recommended to update the application to version 12.2.0.694 with the latest version of the anti-virus databases.

Event History

Nov 20, 2025
CVE Published
via MITRE·06:53 AM
Data Sourced
via MITRE·06:53 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-64984?

CVE-2025-64984 is considered a critical vulnerability impacting various Kaspersky products.

2

How do I fix CVE-2025-64984?

To fix CVE-2025-64984, update Kaspersky Endpoint Security for Linux, Kaspersky Industrial CyberSecurity for Linux Nodes, or Kaspersky Endpoint Security for Mac to the latest versions available after anti-virus databases prior to 18.11.2025.

3

Which Kaspersky products are affected by CVE-2025-64984?

CVE-2025-64984 affects Kaspersky Endpoint Security for Linux, Kaspersky Industrial CyberSecurity for Linux Nodes, and Kaspersky Endpoint Security for Mac with specific versions.

4

What are the consequences of exploiting CVE-2025-64984?

Exploitation of CVE-2025-64984 can lead to unauthorized access and manipulation of the affected systems.

5

When was CVE-2025-64984 announced?

CVE-2025-64984 was announced on a date corresponding to Kaspersky's advisory regarding the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203