Bypass Record
Exploitation for Priv-Esc × Kaspersky Endpoint Security
A publicly-reported instance of Exploitation for Priv-Esc bypassing Kaspersky Endpoint Security, recorded with its original source. Factual record; no assessment of any specific deployment.
Mechanism
The exploit leverages a local privilege escalation flaw in Kaspersky Endpoint Security, allowing a low-privileged user to manipulate a privileged component of the security product. This could enable the attacker to execute code with SYSTEM privileges, bypassing security controls.
Detection & mitigation
Monitor for suspicious process creation or privilege escalation attempts involving Kaspersky Endpoint Security processes. Ensure endpoint detection and response (EDR) telemetry is enabled to detect anomalous behavior, and apply vendor patches as soon as available.
This is a record of a publicly-reported event, not an assessment of any specific organization's deployment. Detection and mitigation notes are drawn from the cited source. Where the source is silent, fields are omitted.