What are the key advantages of Kaspersky Vulnerability and Patch Management Base Plus?
Central console – Managed entirely from the Kaspersky Security Center console.
Vulnerability scanning – Finds flaws across more than 150 supported applications.
Tested rollout – Patches can be trialled before company-wide deployment.
Update control – Can act as your Windows update server.
Audited access – Remote troubleshooting sessions are fully logged.
Important note – No anti-malware protection; Windows endpoints only.
Vulnerability assessment – Detects and prioritises flaws across more than 150 applications.
Patch distribution – Downloads, tests and deploys patches on a defined schedule.
Hardware and software inventory – Records every device, application and licence expiry date.
Operating system deployment – Creates, stores and clones Windows images for PXE rollout.
Remote troubleshooting – Authorised desktop sessions with full logging for audit purposes.
Important – No anti-malware engine; endpoint protection must be licensed separately.
This is a systems management product for Windows endpoints that adds vulnerability scanning, patch deployment and IT inventory to Kaspersky Security Center, the console where all tasks, policies and reports are configured. Kaspersky lists it as the successor to Kaspersky Systems Management, the name under which many administrators still know it, and Base denotes a new licence rather than a renewal of an existing one.
One console – Patching and protection tasks share the same administration server.
Exploit-based prioritisation – Flaws already used by malware are ranked critical first.
Bandwidth control – One branch machine distributes patches to its local colleagues.
Out-of-hours patching – Wake-on-LAN starts machines so users lose no working time.
Evidence reporting – Per-device results show which patches actually installed successfully.
WSUS replacement – The administration server can serve Windows updates directly.
The deciding factor is not headcount but how many different third-party applications you run on Windows and whether anyone has to prove that they were patched. A company with twenty PCs all running the same three Microsoft applications gets little that Windows Update does not already provide. A company with sixty machines running Adobe, Java, browsers and specialist tools has a real inventory problem, and that is where this product starts paying for itself.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | ✓ |
| NIS 2 in the European Union | ✕ | By sector | ✓ |
| Security questionnaire from large customers | ✓ | ✓ | ✓ |
| Patching beyond Microsoft products | Partial | ✓ | ✓ |
| This product fits | Rarely | ✓ | As component |
Since 1 April 2025 the revised Information Security Act has obliged operators of critical infrastructure in Switzerland to report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with a further 14 days to complete an incomplete first report. The accompanying Cybersecurity Ordinance exempts smaller organisations and those below sector thresholds, so most SMEs are not directly obliged to report, although many supply organisations that are. This product supports that obligation in two concrete ways: the hardware and software inventory tells you within minutes which Windows machines run an affected version, and the patch reports document when each fix was actually installed on each device. What it does not do is detect the attack, because it contains no anti-malware and no EDR component, so it will never be the system that starts your 24-hour clock. It also produces no incident timeline and no report format designed for the authority, so the report itself remains manual work. This information is not legal advice; whether your organisation falls under the reporting obligation should be clarified with a qualified adviser.
No software makes a company NIS 2 compliant, because the directive addresses governance, processes and management accountability rather than tooling. NIS 2 requires essential and important entities to take risk-management measures across areas that include incident handling, business continuity, supply chain security, and the handling and disclosure of vulnerabilities. This product maps directly onto the last of those: it identifies known vulnerabilities in Windows software, ranks them by whether malware is already exploiting them, and records the remediation afterwards. It contributes indirectly to supply chain security by keeping an inventory of installed software and its licence status. It does not cover incident handling, business continuity and backup, cryptography or access control policies, staff training, or the governance documentation that auditors ask for first, and none of the accountability the directive places on management can be delegated to a tool.
Two authorities have published measures concerning Kaspersky and both remain in force. On 15 March 2022 the German Federal Office for Information Security (BSI) warned against using Kaspersky antivirus software, on the reasoning that a manufacturer based in Russia could be coerced into offensive operations or be compromised without its own knowledge; the warning has not been withdrawn and was carried over unchanged when Germany revised its information security legislation in December 2025. In the United States, the Department of Commerce issued a final determination in June 2024 barring Kaspersky from new business with US persons from 20 July 2024 and from supplying software updates from 29 September 2024, after which Kaspersky stopped US sales and wound down its US operations. Kaspersky rejects the BSI warning as not based on an objective technical analysis, points to its transparency programme and independent source code reviews, and has formally asked for the warning to be withdrawn. Neither measure rests on a published finding of malicious code in the software; both rest on the vendor's jurisdiction and on the deep system privileges that any security software holds. In practice this matters most if you sell to the public sector, operate under a customer supply chain policy, or have to answer country-of-origin questions in a security questionnaire, and it is a procurement question rather than a functional one.
Yes, for the asset and patching sections, and not at all for the rest. It answers the questions on whether you maintain an inventory of hardware and software, how you identify known vulnerabilities, how you prioritise them, how quickly patches reach endpoints, and whether privileged remote access to workstations is logged, and it produces per-device reports you can attach as evidence rather than describing a process you cannot demonstrate. It does not answer anything about malware protection, detection and response, encryption of laptops and removable media, multi-factor authentication, backup and restore testing, email security, or mobile devices, and it covers only Windows, so any question about your macOS or Linux estate stays unanswered. Country of origin questions are also worth anticipating, given the official assessments described above. To close the patching-adjacent gaps, moving up to Kaspersky Endpoint Security for Business Advanced is usually cheaper and administratively simpler than adding a second vendor, because it includes this same vulnerability and patch management functionality alongside anti-malware and encryption management in one console.
The decisive difference is that this product does not protect anything: it manages and patches, while Endpoint Security for Business Advanced contains the same patch management functionality plus the anti-malware engine and encryption management. Kaspersky sells vulnerability and patch management in four ways: as this standalone targeted solution, as an add-on to Endpoint Security for Business Select, and as an included component of both Endpoint Security for Business Advanced and Total Security for Business. The standalone route makes sense when your endpoint protection is already covered by another vendor or an existing licence and you only need to close the patching gap. If you are buying protection and patching at the same time, compare the Advanced tier before deciding, because buying both separately is rarely the cheaper path.
| Capability | Vulnerability and Patch Management | Endpoint Security for Business Advanced |
|---|---|---|
| Vulnerability scanning and patching | ✓ | ✓ |
| Anti-malware protection | ✕ | ✓ |
| Encryption management | ✕ | ✓ |
| Operating system deployment | ✓ | ✓ |
| Endpoint platforms covered | Windows only | Windows, macOS, Linux |
The product is designed for Windows-based endpoints, so macOS and Linux machines stay outside its scope entirely and mobile devices are not covered at all. It requires a Kaspersky Security Center installation to run, which means the console is a prerequisite rather than an optional extra. Vulnerability detection covers more than 150 popular applications; anything outside that list can still be distributed through custom deployment packages, but it will not be scanned for known vulnerabilities, so verify your specialist software against the supported list before you buy. One regional restriction exists but does not affect this market: Kaspersky has been barred from supplying updates to customers in the United States since 29 September 2024, which is a US-specific measure with no bearing on operation in Switzerland or the European Union. The limitation that most often triggers a follow-up purchase is the absence of anti-malware, because a patching licence alone leaves you without endpoint protection.
Yes. The Kaspersky Security Center administration server can take on the role of a Windows Server Update Services server and distribute Microsoft updates itself. The practical gain is that Microsoft and third-party updates are then approved, scheduled and reported in one place instead of two separate systems.
Vulnerability scanning and update distribution cover more than 150 popular applications, including the browser, runtime and document software that attackers target most often. Severity is assessed by Kaspersky's own analysts alongside additional threat sources, and any flaw known to be actively exploited by malware is automatically treated as critical.
Yes. Applications outside the supported list can be distributed as custom installation packages, scheduled for after hours, and given additional installation parameters where the installer allows it. They will be deployed and inventoried, but not scanned for known vulnerabilities.