CVE-2019-15689: Kaspersky Internet Security

Medium severity, CVSS 6.7. EPSS: 0.8% chance of exploitation in the next 30 days.

Kaspersky Secure Connection, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Security Cloud prior to version 2020 patch E have bug that allows a local user to execute arbitrary code via execution compromised file placed by an attacker with administrator rights. No privilege escalation. Possible whitelisting bypass some of the security products

Affected products

  • Kaspersky Kaspersky Internet Security: version 2019 only
  • Kaspersky Secure Connection: version 3.0 only; version 4.0 only
  • Kaspersky Security Cloud: version 2019 only; version 2020 only
  • Kaspersky Total Security: version 2019 only; version 2020 only

Published 2019-12-02. Last modified 2026-06-17.