CVE-2021-35053
Estado: ModificadaAlta (7.5)—
Possible system denial of service in case of arbitrary changing Firefox browser parameters. An attacker could change specific Firefox browser parameters file in a certain way and then reboot the system to make the system unbootable.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.60%
- Percentil entre todas las CVEs puntuadas: 85
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-noinfo
Referencias
- https://support.kaspersky.com/general/vulnerability.aspx?el=12430#01112021
- https://www.zerodayinitiative.com/advisories/ZDI-21-1280/
- https://www.zerodayinitiative.com/advisories/ZDI-22-431/
- https://support.kaspersky.com/general/vulnerability.aspx?el=12430#01112021
- https://www.zerodayinitiative.com/advisories/ZDI-21-1280/
- https://www.zerodayinitiative.com/advisories/ZDI-22-431/
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-35053",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 6.9,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "vulnerability@kaspersky.com",
"affectedData": [
{
"vendor": "n/a",
"product": "Kaspersky Endpoint Security for Windows",
"versions": [
{
"status": "affected",
"version": "KES versions from 11.1 to 11.6 (inclusively)"
}
]
}
]
}
],
"published": "2021-11-03T20:15:08.347",
"references": [
{
"url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#01112021",
"tags": [
"Broken Link"
],
"source": "vulnerability@kaspersky.com"
},
{
"url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1280/",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "vulnerability@kaspersky.com"
},
{
"url": "https://www.zerodayinitiative.com/advisories/ZDI-22-431/",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "vulnerability@kaspersky.com"
},
{
"url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#01112021",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1280/",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.zerodayinitiative.com/advisories/ZDI-22-431/",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Possible system denial of service in case of arbitrary changing Firefox browser parameters. An attacker could change specific Firefox browser parameters file in a certain way and then reboot the system to make the system unbootable."
},
{
"lang": "es",
"value": "Una posible denegación de servicio del sistema en caso de cambio arbitrario de los parámetros del navegador Firefox. Un atacante podría cambiar un archivo específico de parámetros del navegador Firefox de una manera determinada y luego reiniciar el sistema para hacer que el sistema no pueda arrancar"
}
],
"lastModified": "2026-06-17T03:57:02.977",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:kaspersky:endpoint_security:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C1EAF339-B9C2-4F0D-BAC0-DA29D3BE860D",
"versionEndIncluding": "11.6.0",
"versionStartIncluding": "11.1.0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "vulnerability@kaspersky.com"
}