ZDI-CAN-14235: Kaspersky Password Manager Improper Privilege Management Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Kaspersky Password Manager. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Kaspersky Password Manager Service. The issue results from execution with unnecessary privileges. An attacker can leverage this vulnerability to escalate privileges from medium integrity and execute code in the context of the current user at high integrity.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-14235?
The severity of ZDI-CAN-14235 is classified as critical due to its potential for privilege escalation.
How do I fix ZDI-CAN-14235?
To fix ZDI-CAN-14235, update Kaspersky Password Manager to the latest version as recommended by the vendor.
Who is affected by ZDI-CAN-14235?
ZDI-CAN-14235 affects users of Kaspersky Password Manager installations that are not updated to the latest security patches.
What type of attack is ZDI-CAN-14235 associated with?
ZDI-CAN-14235 is associated with local privilege escalation attacks requiring low-privileged code execution.
What is the cause of ZDI-CAN-14235?
The cause of ZDI-CAN-14235 is a specific flaw in Kaspersky Password Manager that allows for unauthorized privilege escalation.