CVE-2025-64984
Published: Nov 20, 2025
Modified: Nov 20, 2025
CVSS v3.1
6.1
Description
Kaspersky has fixed a security issue in Kaspersky Endpoint Security for Linux (any version with anti-virus databases prior to 18.11.2025), Kaspersky Industrial CyberSecurity for Linux Nodes (any version with anti-virus databases prior to 18.11.2025), and Kaspersky Endpoint Security for Mac (12.0.0.325, 12.1.0.553, and 12.2.0.694 with anti-virus databases prior to 18.11.2025) that could have allowed a reflected XSS attack to be carried out by an attacker using phishing techniques.
| Vendor | Product | Versions |
|---|---|---|
Kaspersky | Kaspersky Endpoint Security | affected 12.0.0.325affected 12.1.0.553unknown 12.2.0.694 |
Kaspersky | Kaspersky Endpoint Security | All versions |
Kaspersky | Kaspersky Industrial CyberSecurity for Linux Nodes | All versions |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now