Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-26200

Опубликовано: 26 фев. 2021
Источник: nvd
CVSS3: 6.8
CVSS2: 4.6
EPSS Низкий

Описание

A component of Kaspersky custom boot loader allowed loading of untrusted UEFI modules due to insufficient check of their authenticity. This component is incorporated in Kaspersky Rescue Disk (KRD) and was trusted by the Authentication Agent of Full Disk Encryption in Kaspersky Endpoint Security (KES). This issue allowed to bypass the UEFI Secure Boot security feature. An attacker would need physical access to the computer to exploit it. Otherwise, local administrator privileges would be required to modify the boot loader component.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:kaspersky:endpoint_security:10:sp2_mr2:*:*:*:*:*:*
cpe:2.3:a:kaspersky:endpoint_security:10:sp2_mr3:*:*:*:*:*:*
cpe:2.3:a:kaspersky:endpoint_security:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:kaspersky:endpoint_security:11.0.1:*:*:*:*:*:*:*
cpe:2.3:a:kaspersky:endpoint_security:11.1.0:*:*:*:*:*:*:*
cpe:2.3:a:kaspersky:rescue_disk:*:*:*:*:*:*:*:*
Версия до 18.0.11.3 (исключая)

EPSS

Процентиль: 10%
0.00034
Низкий

6.8 Medium

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-287

Связанные уязвимости

github
больше 3 лет назад

A component of Kaspersky custom boot loader allowed loading of untrusted UEFI modules due to insufficient check of their authenticity. This component is incorporated in Kaspersky Rescue Disk (KRD) and was trusted by the Authentication Agent of Full Disk Encryption in Kaspersky Endpoint Security (KES). This issue allowed to bypass the UEFI Secure Boot security feature. An attacker would need physical access to the computer to exploit it. Otherwise, local administrator privileges would be required to modify the boot loader component.

CVSS3: 5.3
fstec
почти 5 лет назад

Уязвимость компонента загрузчика средств антивирусной защиты Kaspersky Endpoint Security и образа загрузочного диска Kaspersky Rescue Disk, связанная с недостаточной проверкой подлинности данных, позволяющая нарушителю обойти защитный механизм UEFI Secure Boot

EPSS

Процентиль: 10%
0.00034
Низкий

6.8 Medium

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-287