CVE-2020-25045

Severity CVSS v4.0:
Pending analysis
Type:
CWE-427 Uncontrolled Search Path Element
Publication date:
02/09/2020
Last modified:
11/09/2020

Description

Installers of Kaspersky Security Center and Kaspersky Security Center Web Console prior to 12 & prior to 12 Patch A were vulnerable to a DLL hijacking attack that allowed an attacker to elevate privileges in the system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kaspersky:security_center:*:*:*:*:*:*:*:* 12 (excluding)
cpe:2.3:a:kaspersky:security_center_web_console:*:*:*:*:*:*:*:* 12 (excluding)