The Black Duck Cybersecurity Research Center (CyRC) team has identified a local privilege escalation vulnerability in Kaspersky VPN Secure Connection for Microsoft Windows.
In the Support Tools part of the application, a regular user can use Delete service data and reports to remove a privileged folder.
Based on this capability, an attacker can leverage Arbitrary Folder Delete to SYSTEM EoP to gain SYSTEM privileges.
Publication of CVE-2022-27535 is expected soon from Kaspersky.
Kaspersky VPN Secure Connection 21.3.10.391 (h)
CVSS 3.1 base score: 7.8 (high)
CVSS 3.1 vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Upgrade to version 21.6 or later.
Zeeshan Shaikh (@bugzzzhunter), is a researcher from the Black Duck Cybersecurity Research Center.
FIRST.Org, Inc (FIRST) is a non-profit organization based out of US that owns and manages CVSS. It is not required to be a member of FIRST to utilize or implement CVSS but FIRST does require any individual or organization give appropriate attribution while using CVSS. FIRST also states that any individual or organization that publishes scores follow the guideline so that anyone can understand how the scare was calculated.