A component in Kaspersky Password Manager could allow an attacker to elevate a process Integrity level from Medium to High.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://support.kaspersky.com/general/vulnerability.aspx?el=12430#221121 | vendor advisory |
https://www.zerodayinitiative.com/advisories/ZDI-21-1335/ | third party advisory vdb entry |