Vulnerability Description
The installer of Kaspersky Anti-Ransomware Tool (KART) prior to KART 4.0 Patch C was vulnerable to a DLL hijacking attack that allowed an attacker to elevate privileges during installation process.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kaspersky | Anti-Ransomware Tool | < 4.0 |
Related Weaknesses (CWE)
References
- https://support.kaspersky.com/general/vulnerability.aspx?el=12430#290720Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/192653Third Party Advisory
- https://support.kaspersky.com/general/vulnerability.aspx?el=12430#290720Broken Link
FAQ
What is CVE-2020-28950?
CVE-2020-28950 is a vulnerability with a CVSS score of 7.8 (HIGH). The installer of Kaspersky Anti-Ransomware Tool (KART) prior to KART 4.0 Patch C was vulnerable to a DLL hijacking attack that allowed an attacker to elevate privileges during installation process.
How severe is CVE-2020-28950?
CVE-2020-28950 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-28950?
Check the references section above for vendor advisories and patch information. Affected products include: Kaspersky Anti-Ransomware Tool.