CVE-2024-13614 Details
Description
Kaspersky has fixed a security issue in Kaspersky Anti-Virus SDK for Windows, Kaspersky Security for Virtualization Light Agent, Kaspersky Endpoint Security for Windows, Kaspersky Small Office Security, Kaspersky for Windows (Standard, Plus, Premium), Kaspersky Free, Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Security Cloud, Kaspersky Safe Kids, Kaspersky Anti-Ransomware Tool that could allow an authenticated attacker to write data to a limited area outside the allocated kernel memory buffer. The fix was installed automatically for all Kaspersky Endpoint products.
A vulnerability has been identified in multiple Kaspersky products, including Kaspersky Anti-Virus SDK for Windows, Kaspersky Security for Virtualization Light Agent, Kaspersky Endpoint Security for Windows, Kaspersky Small Office Security, Kaspersky for Windows (Standard, Plus, Premium), Kaspersky Free, Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Security Cloud, Kaspersky Safe Kids, and Kaspersky Anti-Ransomware Tool. This vulnerability could enable an authenticated attacker to write data to a restricted area outside the designated kernel memory buffer. The issue has been automatically resolved in all Kaspersky Endpoint products.
For Kaspersky Anti-Virus SDK for Windows, upgrade to version 8.10.2.2098. For Kaspersky Security for Virtualization Light Agent, install version 5.2.27.319 or later. For all other listed Kaspersky applications, the fix has been applied automatically for those with antivirus databases older than November 5, 2024. Users should ensure their antivirus database is updated to November 6, 2024, or newer.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 6, 2025CISA-ADP
Assessed Feb 6, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.kaspersky.com/vulnerability/list-of-advisories/12430#060225 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-190 | Integer Overflow or Wraparound | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Kaspersky Anti-Virus SDK | 8.10.1.1943 8.10.1.1943 CF |
CPE
Remediation
| |
| Kaspersky Security for Virtualization Light Agent | All versions |
CPE
Remediation
| |
| Kaspersky Endpoint Security | All versions |
CPE
Remediation
| |
| Kaspersky Small Office Security | All versions |
CPE
Remediation
| |
| Kaspersky Standard | All versions |
CPE
Remediation
| |
| Kaspersky Plus | All versions |
CPE
Remediation
| |
| Kaspersky Premium | All versions |
CPE
Remediation
| |
| Kaspersky Free | All versions |
CPE
Remediation
| |
| Kaspersky Anti-Virus | All versions |
CPE
Remediation
| |
| Kaspersky Internet Security | All versions |
CPE
Remediation
| |
| Kaspersky Security Cloud | All versions |
CPE
Remediation
| |
| Kaspersky Safe Kids | All versions |
CPE
Remediation
| |
| Kaspersky Anti-Ransomware Tool | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 6, 2025 | New CVE Received | [email protected] |
Volerion