CVE Tools

Kaspersky Endpoint Security

17 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Kaspersky Endpoint Security, a product in the security products space. Use it to gauge the current risk picture and drill into individual advisories.

Kaspersky Endpoint Security CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Kaspersky Endpoint Security CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-022
2025-030
2025-040
2025-050
2025-060
2025-070
2025-081
2025-090
2025-100
2025-111
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 17 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical16%
  • High529%
  • Medium847%
  • Low318%

Latest CVEs

The 15 most recently published vulnerabilities affecting Kaspersky Endpoint Security.

  1. CVE-2025-64984Kaspersky has fixed a security issue in Kaspersky Endpoint Security for Linux (any version with anti-virus databases prior to 18.11.2025), Kaspersky Industrial CyberSecurity for Linux Nodes (any ve...6.1
  2. BDU:2025-09471Уязвимость средств антивирусной защиты «Лаборатории Касперского», связанная с ошибкой обработки определенных выражений, позволяющая нарушителю выполнить произвольный код с привилегиями SYSTEM8.0
  3. BDU:2025-01472Уязвимость средств антивирусной защиты Kaspersky Virus Removal Tool for Windows, Kaspersky Endpoint Security for Windows, Kaspersky Security for Virtualization Light Agent, Kaspersky Anti-Virus SDK for Windows, Kaspersky Small Office Security, Kaspersky for Windows (Standard, Plus, Premium), Kaspersky Free, Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Security Cloud, связанная с недостатками механизма авторизации, позволяющая нарушителю удалять произвольные файлы или ключи реестра4.4
  4. CVE-2024-13614Kaspersky has fixed a security issue in Kaspersky Anti-Virus SDK for Windows, Kaspersky Security for Virtualization Light Agent, Kaspersky Endpoint Security for Windows, Kaspersky Small Office Secu...5.3
  5. BDU:2024-01525Уязвимость средства антивирусной защиты Kaspersky Endpoint Security для Windows, связанная с небезопасным управлением привилегиями, позволяющая нарушителю приостановить работу защитных модулей3.3
  6. CVE-2023-38039When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API. However, curl did not have a limit in how many or how large hea...7.5
  7. BDU:2022-06573Уязвимость установочного файла средства антивирусной защиты Kaspersky Endpoint Security и утилиты Kavremover, позволяющая нарушителю запустить сторонний исполняемый файл из контекста процесса установки3.3
  8. BDU:2022-06574Уязвимость установочного файла средства антивирусной защиты Kaspersky Endpoint Security и утилиты Kavremover, позволяющая нарушителю запустить исполняемый файл вместо деинсталлятора2.3
  9. CVE-2022-27534Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security with antivirus databases released before 12 March 2022 had a bug in a data parsing module that potentially allowed an attacker...9.8
  10. CVE-2021-27223A denial-of-service issue existed in one of modules that was incorporated in Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security. A local user could cause Windows crash by runnin...5.5
  11. CVE-2021-35053Possible system denial of service in case of arbitrary changing Firefox browser parameters. An attacker could change specific Firefox browser parameters file in a certain way and then reboot the sy...7.5
  12. BDU:2021-02191Уязвимость компонента Безопасные платежи средств антивирусной защиты Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Security Cloud, Kaspersky Small Office Security, Kaspersky Endpoint Security для Windows, позволяющая нарушителю повысить привилегии и выполнить произвольный код5.5
  13. BDU:2021-01779Уязвимость компонента Веб-Антивирус продукта Kaspersky Endpoint Security, позволяющая нарушителю оказать воздействие на целостность данных5.5
  14. CVE-2020-26200A component of Kaspersky custom boot loader allowed loading of untrusted UEFI modules due to insufficient check of their authenticity. This component is incorporated in Kaspersky Rescue Disk (KRD) ...6.8
  15. BDU:2020-02367Уязвимость компонента межпроцессного взаимодействия средств антивирусной защиты Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free, Kaspersky Security Cloud, Kaspersky Password Manager, Kaspersky Safe Kids, Kaspersky Software Updater, Kaspersky Endpoint Security, Kaspersky Small Office Security, Kaspersky Anti Targeted Attack Agent, позволяющая нарушителю выполнить произвольный код8.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store