← Vulnerability feed

Vulnerability record · CVE-2021-27223 · published 1 April 2022

CVE-2021-27223: Kaspersky anti-virus vulnerability

Kaspersky · Anti Virus

A denial-of-service issue existed in one of modules that was incorporated in Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security. A local user could cause Windows crash by running a specially crafted binary module. The fix was delivered automatically. Credits: (Straghkov Denis, Kurmangaleev Shamil, Fedotov Andrey, Kuts Daniil, Mishechkin Maxim, Akolzin Vitaliy) @ ISPRAS

5.5 CVSS 3.1 Medium EPSS 0.20% · top 90.9%
5.5CVSS 3.1 base score, v2 2.1
0.20%EPSS exploitation probability, 30 days
NoNot in CISA KEV
6Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A denial-of-service issue existed in one of modules that was incorporated in Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security. A local user could cause Windows crash by running a specially crafted binary module. The fix was delivered automatically. Credits: (Straghkov Denis, Kurmangaleev Shamil, Fedotov Andrey, Kuts Daniil, Mishechkin Maxim, Akolzin Vitaliy) @ ISPRAS

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-27223 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-27534Kaspersky anti-virus vulnerabilityKaspersky Anti-Virus products for home and Kaspersky Endpoint Security with antivirus databases released before 12 March 2022 had a bug in a data par…EPSS 3.1%9.8CVE-2017-12816Kaspersky internet security incorrect permission assignment vulnerabilityIn Kaspersky Internet Security for Android 11.12.4.1622, some of application exports activities have weak permissions, which might be used by a malwa…EPSS 1.5%7.5CVE-2021-35053Kaspersky endpoint security vulnerabilityPossible system denial of service in case of arbitrary changing Firefox browser parameters. An attacker could change specific Firefox browser paramet…EPSS 2.6%7.5CVE-2017-12817Kaspersky internet security missing encryption vulnerabilityIn Kaspersky Internet Security for Android 11.12.4.1622, some of the application trace files were not encrypted.EPSS 0.86%6.8CVE-2020-26200Kaspersky endpoint security improper authentication vulnerabilityA component of Kaspersky custom boot loader allowed loading of untrusted UEFI modules due to insufficient check of their authenticity. This component…EPSS 0.23%6.7CVE-2019-15689Kaspersky internet security exposure of resource to wrong sphere vulnerabilityKaspersky Secure Connection, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Security Cloud prior to version 2020 patch E have bug t…EPSS 0.77%6.5CVE-2019-15687Kaspersky anti-virus vulnerabilityKaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Se…EPSS 1.6%6.1CVE-2019-15688Kaspersky anti-virus open redirect vulnerabilityKaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Se…EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2021-27223), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.