CVE Database
/

CVE-2025-64984

Back to search

CVE-2025-64984

Published: Nov 20, 2025

Modified: Nov 20, 2025

PUBLISHED

CVSS v3.1

6.1

MEDIUM

Description

Kaspersky has fixed a security issue in Kaspersky Endpoint Security for Linux (any version with anti-virus databases prior to 18.11.2025), Kaspersky Industrial CyberSecurity for Linux Nodes (any version with anti-virus databases prior to 18.11.2025), and Kaspersky Endpoint Security for Mac (12.0.0.325, 12.1.0.553, and 12.2.0.694 with anti-virus databases prior to 18.11.2025) that could have allowed a reflected XSS attack to be carried out by an attacker using phishing techniques.

VendorProductVersions

Kaspersky

Kaspersky Endpoint Security

affected
12.0.0.325
affected
12.1.0.553
unknown
12.2.0.694

Kaspersky

Kaspersky Endpoint Security

All versions

Kaspersky

Kaspersky Industrial CyberSecurity for Linux Nodes

All versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

Required

Scope

Changed

Confidentiality

Low

Integrity

Low

Availability

None

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now