CVE-2022-27535 Vulnerability Details

  /     /     /  

CVE-2022-27535 Metadata Quick Info

CVE Published: 05/08/2022 | CVE Updated: 03/08/2024 | CVE Year: 2022
Source: Kaspersky | Vendor: n/a | Product: Kaspersky VPN Secure Connection for Windows
Status : PUBLISHED

CVE-2022-27535 Description

Kaspersky VPN Secure Connection for Windows version up to 21.5 was vulnerable to arbitrary file deletion via abuse of its \'Delete All Service Data And Reports\' feature by the local authenticated attacker.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Local Privilege Escalation (LPE)
Source: n/a

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).