« Volver al listado

CVE-2020-28950

Estado: ModificadaAlta (7.8)—

The installer of Kaspersky Anti-Ransomware Tool (KART) prior to KART 4.0 Patch C was vulnerable to a DLL hijacking attack that allowed an attacker to elevate privileges during installation process.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-28950",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.9,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.4,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "vulnerability@kaspersky.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Kaspersky Anti-Ransomware Tool",
          "versions": [
            {
              "status": "affected",
              "version": "prior to KART 4.0 Patch C"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-12-04T22:15:12.707",
  "references": [
    {
      "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#290720",
      "tags": [
        "Broken Link"
      ],
      "source": "vulnerability@kaspersky.com"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/192653",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "nvd@nist.gov"
    },
    {
      "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#290720",
      "tags": [
        "Broken Link"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-427"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The installer of Kaspersky Anti-Ransomware Tool (KART) prior to KART 4.0 Patch C was vulnerable to a DLL hijacking attack that allowed an attacker to elevate privileges during installation process."
    },
    {
      "lang": "es",
      "value": "El instalador de Kaspersky Anti-Ransomware Tool (KART) anterior a KART versión 4.0 Parche C era vulnerable a un ataque de secuestro de DLL que permitía a un atacante elevar los privilegios durante el proceso de instalación"
    }
  ],
  "lastModified": "2026-06-17T03:10:54.033",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:kaspersky:anti-ransomware_tool:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5A86E900-1E3B-4605-9BC3-40A327A05B0E",
              "versionEndExcluding": "4.0"
            },
            {
              "criteria": "cpe:2.3:a:kaspersky:anti-ransomware_tool:4.0:patch_c:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "19115E4C-A8FC-4AAF-BFD2-E2305BAC8219"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "vulnerability@kaspersky.com"
}