
Cloud Vulnerability DB
A community-led vulnerabilities database
A security vulnerability (CVE-2021-35053) was discovered in Kaspersky products that could allow an attacker to cause system denial of service. The vulnerability was disclosed on November 1, 2021, affecting multiple Kaspersky products including Kaspersky Anti-Virus, Internet Security, Total Security, Small Office Security, Security Cloud, and Endpoint Security versions 11.1 to 11.6 (Kaspersky Advisory).
The vulnerability exists within Firefox browser parameters handling. An attacker could modify specific Firefox browser parameters file and then reboot the system to make it unbootable. The vulnerability has a CVSS v3.1 base score of 7.5 (HIGH) with vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (NVD).
If successfully exploited, this vulnerability could result in a complete system denial of service condition, making the affected system unbootable after a reboot (ZDI Advisory).
The vulnerability requires the attacker to have the ability to modify Firefox browser parameters and trigger a system reboot. The attack can be performed locally on the affected system (ZDI Advisory).
Kaspersky has released fixes for all affected products. For home products, users should update to version 21.3.10.391(g) or later. For Kaspersky Endpoint Security, users should upgrade to version 11.7. For users unable to update, Kaspersky recommends using Mozilla certificate store instead of Windows certificate store for scanning secure connections in Mozilla Firefox (Kaspersky Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."