
Cloud Vulnerability DB
A community-led vulnerabilities database
A component of Kaspersky custom boot loader allowed loading of untrusted UEFI modules due to insufficient check of their authenticity. This vulnerability (CVE-2020-26200) affected Kaspersky Rescue Disk (KRD) prior to version 18.0.11.3 and Kaspersky Endpoint Security (KES) versions 10 SP2 MR2/MR3 and 11.0.0/11.0.1/11.1.0 with Full Disk Encryption component installed. The vulnerability was discovered and disclosed in February 2021 (NVD, Kaspersky Advisory).
The vulnerability stems from insufficient authentication checks in Kaspersky's custom boot loader component, which is used in both KRD and trusted by the Authentication Agent of Full Disk Encryption in KES. This security flaw allowed the loading of untrusted UEFI modules, effectively bypassing the UEFI Secure Boot security feature. The vulnerability received a CVSS v3.1 base score of 6.8 (MEDIUM) with vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (NVD).
The vulnerability allowed attackers to bypass the UEFI Secure Boot security feature, which is designed to ensure that only trusted code can run during the boot process. This could potentially enable the execution of malicious code during system startup, compromising the security of the affected systems from a very early stage (NVD).
Exploitation of this vulnerability requires either physical access to the affected computer or local administrator privileges to modify the boot loader component. This requirement significantly limits the potential attack surface, though it still presents a serious security risk for systems in environments where physical access cannot be strictly controlled (Kaspersky Advisory).
Kaspersky addressed this vulnerability by releasing updated versions of the affected products. For Kaspersky Rescue Disk, users should upgrade to version 18.0.11.3 (patch C) or later. For Kaspersky Endpoint Security with Full Disk Encryption, users should update to versions newer than the affected releases (10 SP2 MR2/MR3, 11.0.0, 11.0.1, 11.1.0) (Kaspersky Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."