The vulnerability potentially allows an attacker to misuse ESET’s file operations during the module update to delete or move files without having proper permissions.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HEset Endpoint Antivirus
APPEsetall versionsEset Endpoint Security
APPEsetall versionsEset Internet Security
APPEsetall versionsEset Mail Security
APPEsetall versionsEset Nod32
APPEsetall versionsEset Security
APPEsetall versionsEset Server Security
APPEsetall versionsEset Smart Security
APPEsetall versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2020-10180CRITICAL9.8PL ✓same product
Ominięcie wykrywania wirusów w ESET przez zmodyfikowane archiwum BZ2
CVE-2015-8841CRITICAL9.8PL ✓same product
Heap-based buffer overflow w ESET NOD32 — RCE przez plik SIS
CVE-2024-0353HIGH7.8same product
Local privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to d...
CVE-2023-5594HIGH7.5same product
Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermedia...
CVE-2023-2847HIGH7.8same product
During internal security analysis, a local privilege escalation vulnerability has been identified. On a machi...