// For flags

CVE-2024-13614

 

Severity Score

5.3
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track
*SSVC
Descriptions

Kaspersky has fixed a security issue in Kaspersky Anti-Virus SDK for Windows, Kaspersky Security for Virtualization Light Agent, Kaspersky Endpoint Security for Windows, Kaspersky Small Office Security, Kaspersky for Windows (Standard, Plus, Premium), Kaspersky Free, Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Security Cloud, Kaspersky Safe Kids, Kaspersky Anti-Ransomware Tool that could allow an authenticated attacker to write data to a limited area outside the allocated kernel memory buffer. The fix was installed automatically for all Kaspersky Endpoint products.

*Credits: Florian Schweins
CVSS Scores
Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
High
Attack Vector
Local
Attack Complexity
High
Authentication
Single
Confidentiality
None
Integrity
Partial
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:Track
Exploitation
None
Automatable
No
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2025-01-22 CVE Reserved
  • 2025-02-06 CVE Published
  • 2025-02-12 CVE Updated
  • 2025-04-15 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-190: Integer Overflow or Wraparound
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Kaspersky
Search vendor "Kaspersky"
Kaspersky Anti-Virus SDK For Windows
Search vendor "Kaspersky" for product "Kaspersky Anti-Virus SDK For Windows"
8.10.1.1943
Search vendor "Kaspersky" for product "Kaspersky Anti-Virus SDK For Windows" and version "8.10.1.1943"
en
Affected
Kaspersky
Search vendor "Kaspersky"
Kaspersky Security For Virtualization Light Agent
Search vendor "Kaspersky" for product "Kaspersky Security For Virtualization Light Agent"
>= 5.2.0.0 < 5.2.27.319
Search vendor "Kaspersky" for product "Kaspersky Security For Virtualization Light Agent" and version " >= 5.2.0.0 < 5.2.27.319"
en
Affected