CVE-2019-15689 is a local arbitrary code execution vulnerability affecting Kaspersky Secure Connection, Internet Security, Total Security, and Security Cloud products prior to version 2020 patch E. An attacker with administrator rights can exploit this by placing a compromised file, potentially bypassing security product whitelisting. While rated Medium severity (CVSS 6.7) due to high impact on confidentiality, integrity, and availability, it requires high privileges and no user interaction. There is no evidence of active exploitation, public exploit code, or significant community discussion, with only one media article covering the disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2019CPE matchmatch criteria | cpe:2.3:a:kaspersky:kaspersky_internet_security:2019:-:*:*:*:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:kaspersky:kaspersky_internet_security:2019:patch_f:*:*:*:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:kaspersky:kaspersky_internet_security:2019:patch_i:*:*:*:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:kaspersky:kaspersky_internet_security:2019:patch_j:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:a:kaspersky:secure_connection:3.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.