"-Synchronized-Data."

This commit is contained in:
CVE Team 2021-02-26 14:00:37 +00:00
parent 86a18ca180
commit ae02bc2929
No known key found for this signature in database
GPG Key ID: 5708902F06FEF743

View File

@ -4,14 +4,80 @@
"data_version": "4.0",
"CVE_data_meta": {
"ID": "CVE-2020-26200",
"ASSIGNER": "cve@mitre.org",
"STATE": "RESERVED"
"ASSIGNER": "vulnerability@kaspersky.com",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "N/A",
"product": {
"product_data": [
{
"product_name": "Kaspersky Rescue Disk Version",
"version": {
"version_data": [
{
"version_value": "All versions prior to 18.0.11.3 (patch C)"
}
]
}
},
{
"product_name": "Kaspersky Endpoint Security with the Full Disk Encryption component installed",
"version": {
"version_data": [
{
"version_value": "10 SP2 MR2"
},
{
"version_value": "10 SP2 MR3"
},
{
"version_value": "11.0.0"
},
{
"version_value": "11.0.1"
},
{
"version_value": "11.1.0"
}
]
}
}
]
}
}
]
}
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Bypass"
}
]
}
]
},
"references": {
"reference_data": [
{
"refsource": "MISC",
"name": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#170221",
"url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#170221"
}
]
},
"description": {
"description_data": [
{
"lang": "eng",
"value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided."
"value": "A component of Kaspersky custom boot loader allowed loading of untrusted UEFI modules due to insufficient check of their authenticity. This component is incorporated in Kaspersky Rescue Disk (KRD) and was trusted by the Authentication Agent of Full Disk Encryption in Kaspersky Endpoint Security (KES). This issue allowed to bypass the UEFI Secure Boot security feature. An attacker would need physical access to the computer to exploit it. Otherwise, local administrator privileges would be required to modify the boot loader component."
}
]
}