Kaspersky has fixed a security issue in Kaspersky...
Low severity
Unreviewed
Published
Mar 22, 2024
to the GitHub Advisory Database
•
Updated Mar 22, 2024
Description
Published by the National Vulnerability Database
Mar 22, 2024
Published to the GitHub Advisory Database
Mar 22, 2024
Last updated
Mar 22, 2024
Kaspersky has fixed a security issue in Kaspersky Password Manager (KPM) for Windows that allowed a local user to recover the auto-filled credentials from a memory dump when the KPM extension for Google Chrome is used. To exploit the issue, an attacker must trick a user into visiting a login form of a website with the saved credentials, and the KPM extension must autofill these credentials. The attacker must then launch a malware module to steal those specific credentials.
References