CVE Vulnerabilities

CVE-2022-27535

Published: Aug 05, 2022 | Modified: Aug 15, 2022
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Kaspersky VPN Secure Connection for Windows version up to 21.5 was vulnerable to arbitrary file deletion via abuse of its Delete All Service Data And Reports feature by the local authenticated attacker.

Affected Software

Name Vendor Start Version End Version
Vpn_secure_connection Kaspersky * 21.6 (excluding)

References