CVE

CVE-2019-8286

Severity:
MEDIUM
Type:
CWE-200 Information Leak / Disclosure
Publication date:
18/07/2019
Last modified:
26/07/2019

Description

Information Disclosure in Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security versions up to 2019 could potentially disclose unique Product ID by forcing victim to visit a specially crafted webpage (for example, via clicking phishing link). Vulnerability has CVSS v3.0 base score 2.6

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kaspersky:anti-virus:*:*:*:*:*:*:*:* 2019 (including)
cpe:2.3:a:kaspersky:free_anti-virus:*:*:*:*:*:*:*:* 2019 (including)
cpe:2.3:a:kaspersky:internet_security:*:*:*:*:*:*:*:* 2019 (including)
cpe:2.3:a:kaspersky:small_office_security:*:*:*:*:*:*:*:* 6.0 (including)
cpe:2.3:a:kaspersky:total_security:*:*:*:*:*:*:*:* 2019 (including)