CVE-2020-26200 - CVE House
Back to Database
Status published Medium CVE-2020-26200

A component of Kaspersky custom boot loader allowed loading of...

Vulnerability Description

A component of Kaspersky custom boot loader allowed loading of untrusted UEFI modules due to insufficient check of their authenticity. This component is incorporated in Kaspersky Rescue Disk (KRD) and was trusted by the Authentication Agent of Full Disk Encryption in Kaspersky Endpoint Security (KES). This issue allowed to bypass the UEFI Secure Boot security feature. An attacker would need physical access to the computer to exploit it. Otherwise, local administrator privileges would be required to modify the boot loader component.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-26200

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Kaspersky Rescue Disk Version, Kaspersky Endpoint Security with the Full Disk Encryption component installed
Vulnerable Versions:
All versions prior to 18.0.11.3 (patch C), 10 SP2 MR2, 10 SP2 MR3, 11.0.0, 11.0.1, 11.1.0

Timeline

Official Publish: February 26th, 2021
Last Modified: August 4th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.