HIGH🇵🇱 Wersja polska

CVE-2023-2847

CVSS 7.8v3.1pub. 2023-06-15upd. 2024-11-21

During internal security analysis, a local privilege escalation vulnerability has been identified. On a machine with the affected ESET product installed, it was possible for a user with lower privileges due to improper privilege management to trigger actions with root privileges. ESET remedied this possible attack vector and has prepared new builds of its products that are no longer susceptible to this vulnerability.

CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
  • Eset Cyber Security

    APP
    Eset
    7.3.0 – 7.3.3700.0 (excl.)
  • Eset Endpoint Antivirus

    APP
    Eset
    < 8.1.12.07.0.0 – 7.3.3600.0 (excl.)9.0.5.0 – 9.0.10.0 (excl.)9.1.4.0 – 9.1.11.0 (excl.)
  • Eset Server Security

    APP
    Eset
    < 8.1.823.09.0.464.0 – 9.0.466.0 (excl.)9.1.96.0 – 9.1.98.0 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
LPE
CWE
References

Related vulnerabilities

CVE-2020-10180CRITICAL9.8PL ✓same product

Ominięcie wykrywania wirusów w ESET przez zmodyfikowane archiwum BZ2

CVE-2024-0353HIGH7.8same product

Local privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to d...

CVE-2023-5594HIGH7.5same product

Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermedia...

CVE-2023-3160HIGH7.8same product

The vulnerability potentially allows an attacker to misuse ESET’s file operations during the module update to...

CVE-2021-37851HIGH7.3same product

Local privilege escalation in Windows products of ESET allows user who is logged into the system to exploit re...