Search

Find a vulnerability

Search criteria

    190 vulnerabilities by ESET

    CERTFR-2026-AVI-1143

    Vulnerability from certfr_avis - Published: 2026-09-09 - Updated: 2026-09-09

    Une vulnérabilité a été découverte dans les produits ESET. Elle permet à un attaquant de provoquer une élévation de privilèges.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    ESET AV Remover AV Remover versions antérieures à 1.6.17.0
    References
    Bulletin de sécurité ESET ca9000 2026-09-09 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "AV Remover versions ant\u00e9rieures \u00e0 1.6.17.0",
          "product": {
            "name": "AV Remover",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-12858",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-12858"
        }
      ],
      "initial_release_date": "2026-09-09T00:00:00",
      "last_revision_date": "2026-09-09T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-1143",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-09-09T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "\u00c9l\u00e9vation de privil\u00e8ges"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans les produits ESET. Elle permet \u00e0 un attaquant de provoquer une \u00e9l\u00e9vation de privil\u00e8ges.",
      "title": "Vuln\u00e9rabilit\u00e9 dans les produits ESET",
      "vendor_advisories": [
        {
          "published_at": "2026-09-09",
          "title": "Bulletin de s\u00e9curit\u00e9 ESET ca9000",
          "url": "https://support-feed.eset.com/link/15370/17443273/ca9000"
        }
      ]
    }

    CERTFR-2026-AVI-0932

    Vulnerability from certfr_avis - Published: 2026-07-24 - Updated: 2026-07-24

    De multiples vulnérabilités ont été découvertes dans les produits ESET. Elles permettent à un attaquant de provoquer une élévation de privilèges.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    ESET Endpoint Security Endpoint Security pour macOS versions antérieures à 8.1.300.0
    ESET Endpoint Security Endpoint Security pour macOS versions 9.0.x antérieures à 9.0.6400.0
    ESET Cyber Security Cyber Security pour macOS versions antérieures à 9.0.6300.0
    ESET Endpoint Security Endpoint Security pour macOS versions 9.1.x antérieures à 9.1.3100.0
    References
    Bulletin de sécurité ESET ca8977 2026-07-24 vendor-advisory
    Bulletin de sécurité ESET ca8974 2026-07-24 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Endpoint Security pour macOS versions ant\u00e9rieures \u00e0 8.1.300.0",
          "product": {
            "name": "Endpoint Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Endpoint Security pour macOS versions 9.0.x ant\u00e9rieures \u00e0 9.0.6400.0",
          "product": {
            "name": "Endpoint Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Cyber Security pour macOS versions ant\u00e9rieures \u00e0 9.0.6300.0",
          "product": {
            "name": "Cyber Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Endpoint Security pour macOS versions 9.1.x ant\u00e9rieures \u00e0 9.1.3100.0",
          "product": {
            "name": "Endpoint Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-7483",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-7483"
        },
        {
          "name": "CVE-2026-10610",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-10610"
        }
      ],
      "initial_release_date": "2026-07-24T00:00:00",
      "last_revision_date": "2026-07-24T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-0932",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-07-24T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "\u00c9l\u00e9vation de privil\u00e8ges"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits ESET. Elles permettent \u00e0 un attaquant de provoquer une \u00e9l\u00e9vation de privil\u00e8ges.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits ESET",
      "vendor_advisories": [
        {
          "published_at": "2026-07-24",
          "title": "Bulletin de s\u00e9curit\u00e9 ESET ca8977",
          "url": "https://support-feed.eset.com/link/15370/17386417/ca8977"
        },
        {
          "published_at": "2026-07-24",
          "title": "Bulletin de s\u00e9curit\u00e9 ESET ca8974",
          "url": "https://support-feed.eset.com/link/15370/17386418/ca8974"
        }
      ]
    }

    CERTFR-2026-AVI-0892

    Vulnerability from certfr_avis - Published: 2026-07-16 - Updated: 2026-07-16

    Une vulnérabilité a été découverte dans les produits ESET. Elle permet à un attaquant de provoquer un déni de service.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    ESET Server Security Server Security versions 12.1.x antérieures à 12.1.407.0
    ESET Server Security Server Security versions 13.1.x antérieures à 13.1.118.0
    ESET Server Security Server Security versions 13.0.x antérieures à 13.0.36.0
    ESET Endpoint Antivirus Endpoint Antivirus versions 12.2.x antérieures à 12.2.9.0
    ESET Endpoint Antivirus Endpoint Antivirus versions 13.0.x antérieures à 13.0.5.0
    ESET Endpoint Antivirus Endpoint Antivirus versions 13.1.x antérieures à 13.1.5.0
    ESET Server Security Server Security versions 12.0.x antérieures à 12.0.292.0
    ESET Endpoint Antivirus Endpoint Antivirus versions 13.2.x antérieures à 13.2.3.0
    ESET Server Security Server Security versions 13.2.x antérieures à 13.2.53.0
    ESET Endpoint Antivirus Endpoint Antivirus versions 12.0.x antérieures à 12.0.14.0
    ESET Endpoint Antivirus Endpoint Antivirus versions 12.1.x antérieures à 12.1.2.0
    ESET Server Security Server Security versions 12.2.x antérieures à 12.2.73.0
    References
    Bulletin de sécurité ESET ca8972 2026-07-15 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Server Security versions 12.1.x ant\u00e9rieures \u00e0 12.1.407.0",
          "product": {
            "name": "Server Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Server Security versions 13.1.x ant\u00e9rieures \u00e0 13.1.118.0",
          "product": {
            "name": "Server Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Server Security versions 13.0.x ant\u00e9rieures \u00e0 13.0.36.0",
          "product": {
            "name": "Server Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Endpoint Antivirus versions 12.2.x ant\u00e9rieures \u00e0 12.2.9.0",
          "product": {
            "name": "Endpoint Antivirus",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Endpoint Antivirus versions 13.0.x ant\u00e9rieures \u00e0 13.0.5.0",
          "product": {
            "name": "Endpoint Antivirus",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Endpoint Antivirus versions 13.1.x ant\u00e9rieures \u00e0 13.1.5.0",
          "product": {
            "name": "Endpoint Antivirus",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Server Security versions 12.0.x ant\u00e9rieures \u00e0 12.0.292.0",
          "product": {
            "name": "Server Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Endpoint Antivirus versions 13.2.x ant\u00e9rieures \u00e0 13.2.3.0",
          "product": {
            "name": "Endpoint Antivirus",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Server Security versions 13.2.x ant\u00e9rieures \u00e0 13.2.53.0",
          "product": {
            "name": "Server Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Endpoint Antivirus versions 12.0.x ant\u00e9rieures \u00e0 12.0.14.0",
          "product": {
            "name": "Endpoint Antivirus",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Endpoint Antivirus versions 12.1.x ant\u00e9rieures \u00e0 12.1.2.0",
          "product": {
            "name": "Endpoint Antivirus",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Server Security versions 12.2.x ant\u00e9rieures \u00e0 12.2.73.0",
          "product": {
            "name": "Server Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-6424",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6424"
        }
      ],
      "initial_release_date": "2026-07-16T00:00:00",
      "last_revision_date": "2026-07-16T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-0892",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-07-16T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans les produits ESET. Elle permet \u00e0 un attaquant de provoquer un d\u00e9ni de service.",
      "title": "Vuln\u00e9rabilit\u00e9 dans les produits ESET",
      "vendor_advisories": [
        {
          "published_at": "2026-07-15",
          "title": "Bulletin de s\u00e9curit\u00e9 ESET ca8972",
          "url": "https://support-feed.eset.com/link/15370/17380664/ca8972"
        }
      ]
    }

    CERTFR-2026-AVI-0882

    Vulnerability from certfr_avis - Published: 2026-07-15 - Updated: 2026-07-15

    Une vulnérabilité a été découverte dans ESET Inspect Connector. Elle permet à un attaquant de provoquer une élévation de privilèges.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    ESET Inspect Connector Inspect Connector versions antérieures à 3.1.6017.0 pour Windows
    References
    Bulletin de sécurité ESET ca8970 2026-07-14 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Inspect Connector versions ant\u00e9rieures \u00e0 3.1.6017.0 pour Windows",
          "product": {
            "name": "Inspect Connector",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-6423",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6423"
        }
      ],
      "initial_release_date": "2026-07-15T00:00:00",
      "last_revision_date": "2026-07-15T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-0882",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-07-15T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "\u00c9l\u00e9vation de privil\u00e8ges"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans ESET Inspect Connector. Elle permet \u00e0 un attaquant de provoquer une \u00e9l\u00e9vation de privil\u00e8ges.",
      "title": "Vuln\u00e9rabilit\u00e9 dans ESET Inspect Connector",
      "vendor_advisories": [
        {
          "published_at": "2026-07-14",
          "title": "Bulletin de s\u00e9curit\u00e9 ESET ca8970",
          "url": "https://support-feed.eset.com/link/15370/17380063/ca8970"
        }
      ]
    }

    CERTFR-2026-AVI-0111

    Vulnerability from certfr_avis - Published: 2026-02-02 - Updated: 2026-02-02

    Une vulnérabilité a été découverte dans ESET Inspect Connector. Elle permet à un attaquant de provoquer une élévation de privilèges.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    ESET Inspect Connector Inspect Connector versions antérieures à 3.0.5765 sur Windows
    References
    Bulletin de sécurité ESET ca8910 2026-01-30 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Inspect Connector versions ant\u00e9rieures \u00e0 3.0.5765 sur Windows",
          "product": {
            "name": "Inspect Connector",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2025-13176",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-13176"
        }
      ],
      "initial_release_date": "2026-02-02T00:00:00",
      "last_revision_date": "2026-02-02T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-0111",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-02-02T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "\u00c9l\u00e9vation de privil\u00e8ges"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans ESET Inspect Connector. Elle permet \u00e0 un attaquant de provoquer une \u00e9l\u00e9vation de privil\u00e8ges.",
      "title": "Vuln\u00e9rabilit\u00e9 dans ESET Inspect Connector",
      "vendor_advisories": [
        {
          "published_at": "2026-01-30",
          "title": "Bulletin de s\u00e9curit\u00e9 ESET ca8910",
          "url": "https://support-feed.eset.com/link/15370/17266505/ca8910"
        }
      ]
    }

    CERTFR-2025-AVI-0727

    Vulnerability from certfr_avis - Published: 2025-08-25 - Updated: 2025-08-25

    De multiples vulnérabilités ont été découvertes dans les produits ESET. Elles permettent à un attaquant de provoquer un déni de service à distance et un problème de sécurité non spécifié par l'éditeur.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    ESET Server Security Server Security pour Windows Server (anciennement File Security pour Microsoft Windows Server) sans le dernier correctif de sécurité
    ESET Mail Security Mail Security pour Microsoft Exchange Server sans le dernier correctif de sécurité
    ESET File Security File Security pour Microsoft Azure sans le dernier correctif de sécurité
    ESET PROTECT On-Prem PROTECT On-Prem versions 12.1.x antérieures à 12.1.11.0
    ESET Security Ultimate Security Ultimate sans le dernier correctif de sécurité
    ESET Endpoint Antivirus Endpoint Antivirus pour Windows sans le dernier correctif de sécurité
    ESET Endpoint Security Endpoint Security pour Windows sans le dernier correctif de sécurité
    ESET Security Security pour Microsoft SharePoint Server sans le dernier correctif de sécurité
    ESET Safe Server Safe Server sans le dernier correctif de sécurité
    ESET Small Business Security Small Business Security sans le dernier correctif de sécurité
    ESET PROTECT On-Prem PROTECT On-Prem versions 11.1.x antérieures à 11.1.18.0
    ESET Smart Security Premium Smart Security Premium sans le dernier correctif de sécurité
    ESET NOD32 Antivirus NOD32 Antivirus sans le dernier correctif de sécurité
    ESET PROTECT On-Prem PROTECT On-Prem versions 12.0.x antérieures à 12.0.15.0
    ESET Mail Security Mail Security pour IBM Domino sans le dernier correctif de sécurité
    ESET Internet Security Internet Security sans le dernier correctif de sécurité
    References
    Bulletin de sécurité ESET ca8854 2025-08-21 vendor-advisory
    Bulletin de sécurité ESET ca8853 2025-08-21 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Server Security pour Windows Server (anciennement File Security pour Microsoft Windows Server) sans le dernier correctif de s\u00e9curit\u00e9",
          "product": {
            "name": "Server Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Mail Security pour Microsoft Exchange Server sans le dernier correctif de s\u00e9curit\u00e9",
          "product": {
            "name": "Mail Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "File Security pour Microsoft Azure sans le dernier correctif de s\u00e9curit\u00e9",
          "product": {
            "name": "File Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "PROTECT On-Prem versions 12.1.x ant\u00e9rieures \u00e0 12.1.11.0",
          "product": {
            "name": "PROTECT On-Prem",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Security Ultimate sans le dernier correctif de s\u00e9curit\u00e9",
          "product": {
            "name": "Security Ultimate",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Endpoint Antivirus pour Windows sans le dernier correctif de s\u00e9curit\u00e9",
          "product": {
            "name": "Endpoint Antivirus",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Endpoint Security pour Windows sans le dernier correctif de s\u00e9curit\u00e9",
          "product": {
            "name": "Endpoint Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Security pour Microsoft SharePoint Server sans le dernier correctif de s\u00e9curit\u00e9\n\n",
          "product": {
            "name": "Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Safe Server sans le dernier correctif de s\u00e9curit\u00e9",
          "product": {
            "name": "Safe Server",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Small Business Security sans le dernier correctif de s\u00e9curit\u00e9",
          "product": {
            "name": "Small Business Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "PROTECT On-Prem versions 11.1.x ant\u00e9rieures \u00e0 11.1.18.0",
          "product": {
            "name": "PROTECT On-Prem",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Smart Security Premium sans le dernier correctif de s\u00e9curit\u00e9",
          "product": {
            "name": "Smart Security Premium",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "NOD32 Antivirus sans le dernier correctif de s\u00e9curit\u00e9",
          "product": {
            "name": "NOD32 Antivirus",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "PROTECT On-Prem versions 12.0.x ant\u00e9rieures \u00e0 12.0.15.0",
          "product": {
            "name": "PROTECT On-Prem",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Mail Security pour IBM Domino sans le dernier correctif de s\u00e9curit\u00e9\n",
          "product": {
            "name": "Mail Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Internet Security sans le dernier correctif de s\u00e9curit\u00e9\n",
          "product": {
            "name": "Internet Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2025-8352",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-8352"
        },
        {
          "name": "CVE-2025-4952",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-4952"
        },
        {
          "name": "CVE-2025-48976",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-48976"
        },
        {
          "name": "CVE-2025-48988",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-48988"
        }
      ],
      "initial_release_date": "2025-08-25T00:00:00",
      "last_revision_date": "2025-08-25T00:00:00",
      "links": [],
      "reference": "CERTFR-2025-AVI-0727",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2025-08-25T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits ESET. Elles permettent \u00e0 un attaquant de provoquer un d\u00e9ni de service \u00e0 distance et un probl\u00e8me de s\u00e9curit\u00e9 non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits ESET",
      "vendor_advisories": [
        {
          "published_at": "2025-08-21",
          "title": "Bulletin de s\u00e9curit\u00e9 ESET ca8854",
          "url": "https://support-feed.eset.com/link/15370/17124579/ca8854"
        },
        {
          "published_at": "2025-08-21",
          "title": "Bulletin de s\u00e9curit\u00e9 ESET ca8853",
          "url": "https://support-feed.eset.com/link/15370/17124580/ca8853"
        }
      ]
    }

    CERTFR-2025-AVI-0623

    Vulnerability from certfr_avis - Published: 2025-07-25 - Updated: 2025-07-25

    De multiples vulnérabilités ont été découvertes dans les produits ESET. Elles permettent à un attaquant de provoquer une élévation de privilèges et une atteinte à l'intégrité des données.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    ESET Endpoint Security Endpoint Security versions antérieures à 11.1.2062.0 pour Windows
    ESET Small Business Security Small Business Security versions antérieures à 18.2.14.0
    ESET Security Security versions 11.x antérieures à 11.1.15005.0 pour Microsoft SharePoint Server
    ESET Mail Security Mail Security versions 11.x antérieures à 11.1.10013 pour Microsoft Exchange Server
    ESET Internet Security Internet Security versions antérieures à 18.2.14.0
    ESET Server Security Server Security versions 12.x antérieures à 12.0.12005.0 pour Windows
    ESET Smart Security Premium Smart Security Premium versions antérieures à 18.2.14.0
    ESET Security Security versions 12.x antérieures à 12.0.15005.0 pour Microsoft SharePoint Server
    ESET Safe Server Safe Server versions antérieures à 18.2.14.0
    ESET Security Ultimate Security Ultimate versions antérieures à 18.2.14.0
    ESET Server Security Server Security versions 11.x antérieures à 11.1.12013.0 pour Windows
    ESET Mail Security Mail Security versions 12.x antérieures à 12.0.10004.0 pour Microsoft Exchange Server
    ESET Endpoint Antivirus Endpoint Antivirus versions antérieures à 12.0.2058.0 pour Windows
    ESET NOD32 Antivirus NOD32 Antivirus versions antérieures à 18.2.14.0
    References
    Bulletin de sécurité ESET ca8840 2025-07-16 vendor-advisory
    Bulletin de sécurité ESET ca8838 2025-07-09 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Endpoint Security versions ant\u00e9rieures \u00e0 11.1.2062.0 pour Windows",
          "product": {
            "name": "Endpoint Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Small Business Security versions ant\u00e9rieures \u00e0 18.2.14.0",
          "product": {
            "name": "Small Business Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Security versions 11.x ant\u00e9rieures \u00e0 11.1.15005.0 pour Microsoft SharePoint Server",
          "product": {
            "name": "Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Mail Security versions 11.x ant\u00e9rieures \u00e0 11.1.10013 pour Microsoft Exchange Server",
          "product": {
            "name": "Mail Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Internet Security versions ant\u00e9rieures \u00e0 18.2.14.0",
          "product": {
            "name": "Internet Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Server Security versions 12.x ant\u00e9rieures \u00e0 12.0.12005.0 pour Windows",
          "product": {
            "name": "Server Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Smart Security Premium versions ant\u00e9rieures \u00e0 18.2.14.0",
          "product": {
            "name": "Smart Security Premium",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Security versions 12.x ant\u00e9rieures \u00e0 12.0.15005.0 pour Microsoft SharePoint Server",
          "product": {
            "name": "Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Safe Server versions ant\u00e9rieures \u00e0 18.2.14.0",
          "product": {
            "name": "Safe Server",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Security Ultimate versions ant\u00e9rieures \u00e0 18.2.14.0",
          "product": {
            "name": "Security Ultimate",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Server Security versions 11.x ant\u00e9rieures \u00e0 11.1.12013.0 pour Windows",
          "product": {
            "name": "Server Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Mail Security versions 12.x ant\u00e9rieures \u00e0 12.0.10004.0 pour Microsoft Exchange Server",
          "product": {
            "name": "Mail Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Endpoint Antivirus versions ant\u00e9rieures \u00e0 12.0.2058.0 pour Windows",
          "product": {
            "name": "Endpoint Antivirus",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "NOD32 Antivirus versions ant\u00e9rieures \u00e0 18.2.14.0",
          "product": {
            "name": "NOD32 Antivirus",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2025-5028",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5028"
        },
        {
          "name": "CVE-2025-2425",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-2425"
        }
      ],
      "initial_release_date": "2025-07-25T00:00:00",
      "last_revision_date": "2025-07-25T00:00:00",
      "links": [],
      "reference": "CERTFR-2025-AVI-0623",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2025-07-25T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
        },
        {
          "description": "\u00c9l\u00e9vation de privil\u00e8ges"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits ESET. Elles permettent \u00e0 un attaquant de provoquer une \u00e9l\u00e9vation de privil\u00e8ges et une atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits ESET",
      "vendor_advisories": [
        {
          "published_at": "2025-07-16",
          "title": "Bulletin de s\u00e9curit\u00e9 ESET ca8840",
          "url": "https://support-feed.eset.com/link/15370/17103529/ca8840"
        },
        {
          "published_at": "2025-07-09",
          "title": "Bulletin de s\u00e9curit\u00e9 ESET ca8838",
          "url": "https://support-feed.eset.com/link/15370/17103530/ca8838"
        }
      ]
    }

    CERTFR-2025-AVI-0280

    Vulnerability from certfr_avis - Published: 2025-04-07 - Updated: 2025-04-07

    Une vulnérabilité a été découverte dans les produits ESET. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    ESET Smart Security Premium Smart Security Premium versions antériéures à 18.1.10.0
    ESET Server Security Server Security versions antérieures à 11.1.12009.0 pour Windows Server
    ESET NOD32 Antivirus NOD32 Antivirus versions antériéures à 18.1.10.0
    ESET Internet Security Internet Security versions antériéures à 18.1.10.0
    ESET Endpoint Security Endpoint Security versions antérieures à 12.0.2045.0
    ESET Endpoint Antivirus Endpoint Antivirus versions antérieures à 12.0.2045.0
    ESET Mail Security Mail Security versions antérieures à 11.1.10011.0, 11.0.10010.0 et 10.1.10017.0 pour Microsoft Exchange Server
    ESET Security Ultimate Security Ultimate versions antériéures à 18.1.10.0
    ESET Endpoint Antivirus Endpoint Antivirus versions antérieures à 11.1.2059.0
    ESET Security Security versions antérieures à 11.1.15003.0, 11.0.15007.0, 10.0.15008.0 pour Microsoft SharePoint Server
    ESET Safe Server ESET Safe Server versions antérieures à 18.1.10.0
    ESET Endpoint Security Endpoint Security versions antérieures à 11.1.2059.0
    ESET Small Business Security Small Business Security versions antérieures à 18.1.10.0
    References
    Bulletin de sécurité ESET CA8810 2025-04-04 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "Smart Security Premium versions ant\u00e9ri\u00e9ures \u00e0 18.1.10.0",
          "product": {
            "name": "Smart Security Premium",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Server Security versions ant\u00e9rieures \u00e0 11.1.12009.0 pour Windows Server",
          "product": {
            "name": "Server Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "NOD32 Antivirus versions ant\u00e9ri\u00e9ures \u00e0 18.1.10.0",
          "product": {
            "name": "NOD32 Antivirus",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Internet Security versions ant\u00e9ri\u00e9ures \u00e0 18.1.10.0",
          "product": {
            "name": "Internet Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Endpoint Security versions ant\u00e9rieures \u00e0 12.0.2045.0",
          "product": {
            "name": "Endpoint Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Endpoint Antivirus versions ant\u00e9rieures \u00e0 12.0.2045.0",
          "product": {
            "name": "Endpoint Antivirus",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Mail Security versions ant\u00e9rieures \u00e0 11.1.10011.0, 11.0.10010.0 et 10.1.10017.0 pour Microsoft Exchange Server",
          "product": {
            "name": "Mail Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Security Ultimate versions ant\u00e9ri\u00e9ures \u00e0 18.1.10.0",
          "product": {
            "name": "Security Ultimate",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Endpoint Antivirus versions ant\u00e9rieures \u00e0 11.1.2059.0",
          "product": {
            "name": "Endpoint Antivirus",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Security versions ant\u00e9rieures \u00e0 11.1.15003.0, 11.0.15007.0, 10.0.15008.0 pour Microsoft SharePoint Server",
          "product": {
            "name": "Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Safe Server versions ant\u00e9rieures \u00e0 18.1.10.0",
          "product": {
            "name": "Safe Server",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Endpoint Security versions ant\u00e9rieures \u00e0 11.1.2059.0",
          "product": {
            "name": "Endpoint Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "Small Business Security versions ant\u00e9rieures \u00e0 18.1.10.0",
          "product": {
            "name": "Small Business Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2024-11859",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-11859"
        }
      ],
      "initial_release_date": "2025-04-07T00:00:00",
      "last_revision_date": "2025-04-07T00:00:00",
      "links": [],
      "reference": "CERTFR-2025-AVI-0280",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2025-04-07T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans les produits ESET. Elle permet \u00e0 un attaquant de provoquer un contournement de la politique de s\u00e9curit\u00e9.",
      "title": "Vuln\u00e9rabilit\u00e9 dans les produits ESET",
      "vendor_advisories": [
        {
          "published_at": "2025-04-04",
          "title": "Bulletin de s\u00e9curit\u00e9 ESET CA8810",
          "url": "https://support-feed.eset.com/link/15370/16999046/ca8810"
        }
      ]
    }

    CERTFR-2024-AVI-0801

    Vulnerability from certfr_avis - Published: 2024-09-23 - Updated: 2024-09-23

    De multiples vulnérabilités ont été découvertes dans les produits ESET. Elles permettent à un attaquant de provoquer une élévation de privilèges et un déni de service.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    ESET Safe Server ESET Safe Server sans le correctif de sécurité Cleaner module 1251
    ESET Small Business Security ESET Small Business Security sans le correctif de sécurité Cleaner module 1251
    ESET Security Ultimate ESET Security Ultimate sans le correctif de sécurité Cleaner module 1251
    ESET Endpoint Security ESET Endpoint Security sans le correctif de sécurité Cleaner module 1251 pour Windows
    ESET File Security ESET File Security sans le correctif de sécurité Cleaner module 1251 pour Microsoft Azure
    ESET NOD32 Antivirus ESET NOD32 Antivirus sans le correctif de sécurité Cleaner module 1251
    ESET Internet Security ESET Internet Security sans le correctif de sécurité Cleaner module 1251
    ESET Mail Security ESET Mail Security sans le correctif de sécurité Cleaner module 1251 pour Microsoft Exchange Server et IBM Domino
    ESET Smart Security Premium ESET Smart Security Premium sans le correctif de sécurité Cleaner module 1251
    ESET Server Security ESET Server Security sans le correctif de sécurité Cleaner module 1251 pour Windows Server
    ESET Endpoint Security ESET Endpoint Security versions antérieures à 8.0.7200.0 pour macOS
    ESET Cyber Security ESET Cyber Security versions antérieures à 7.5.74.0
    ESET Endpoint Antivirus ESET Endpoint Antivirus sans le correctif de sécurité Cleaner module 1251
    ESET Security ESET Security sans le correctif de sécurité Cleaner module 1251 pour Microsoft SharePoint Server
    References
    Bulletin de sécurité ESET ca8725 2024-09-20 vendor-advisory
    Bulletin de sécurité ESET ca8726 2024-09-20 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "ESET Safe Server sans le correctif de s\u00e9curit\u00e9 Cleaner module 1251",
          "product": {
            "name": "Safe Server",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Small Business Security sans le correctif de s\u00e9curit\u00e9 Cleaner module 1251",
          "product": {
            "name": "Small Business Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Security Ultimate sans le correctif de s\u00e9curit\u00e9 Cleaner module 1251",
          "product": {
            "name": "Security Ultimate",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Endpoint Security sans le correctif de s\u00e9curit\u00e9 Cleaner module 1251 pour Windows",
          "product": {
            "name": "Endpoint Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET File Security sans le correctif de s\u00e9curit\u00e9 Cleaner module 1251 pour Microsoft Azure",
          "product": {
            "name": "File Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET NOD32 Antivirus sans le correctif de s\u00e9curit\u00e9 Cleaner module 1251",
          "product": {
            "name": "NOD32 Antivirus",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Internet Security sans le correctif de s\u00e9curit\u00e9 Cleaner module 1251",
          "product": {
            "name": "Internet Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Mail Security sans le correctif de s\u00e9curit\u00e9 Cleaner module 1251 pour Microsoft Exchange Server et IBM Domino ",
          "product": {
            "name": "Mail Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Smart Security Premium sans le correctif de s\u00e9curit\u00e9 Cleaner module 1251",
          "product": {
            "name": "Smart Security Premium",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Server Security sans le correctif de s\u00e9curit\u00e9 Cleaner module 1251 pour Windows Server",
          "product": {
            "name": "Server Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Endpoint Security versions ant\u00e9rieures \u00e0 8.0.7200.0 pour macOS ",
          "product": {
            "name": "Endpoint Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Cyber Security versions ant\u00e9rieures \u00e0 7.5.74.0 ",
          "product": {
            "name": "Cyber Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Endpoint Antivirus sans le correctif de s\u00e9curit\u00e9 Cleaner module 1251",
          "product": {
            "name": "Endpoint Antivirus",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Security sans le correctif de s\u00e9curit\u00e9 Cleaner module 1251 pour Microsoft SharePoint Server",
          "product": {
            "name": "Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2024-6654",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-6654"
        },
        {
          "name": "CVE-2024-7400",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-7400"
        }
      ],
      "initial_release_date": "2024-09-23T00:00:00",
      "last_revision_date": "2024-09-23T00:00:00",
      "links": [],
      "reference": "CERTFR-2024-AVI-0801",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2024-09-23T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service"
        },
        {
          "description": "\u00c9l\u00e9vation de privil\u00e8ges"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits ESET. Elles permettent \u00e0 un attaquant de provoquer une \u00e9l\u00e9vation de privil\u00e8ges et un d\u00e9ni de service.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits ESET",
      "vendor_advisories": [
        {
          "published_at": "2024-09-20",
          "title": "Bulletin de s\u00e9curit\u00e9 ESET ca8725",
          "url": "https://support-feed.eset.com/link/15370/16815452/ca8725"
        },
        {
          "published_at": "2024-09-20",
          "title": "Bulletin de s\u00e9curit\u00e9 ESET ca8726",
          "url": "https://support-feed.eset.com/link/15370/16815451/ca8726"
        }
      ]
    }

    CERTFR-2024-AVI-0581

    Vulnerability from certfr_avis - Published: 2024-07-15 - Updated: 2024-07-15

    Une vulnérabilité a été découverte dans les produits ESET. Elle permet à un attaquant de provoquer une atteinte à l'intégrité des données et un déni de service.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    ESET Smart Security Premium ESET Smart Security Premium versions antérieures à 17.2.7.0
    ESET Mail Security ESET Mail Security versions antérieures à 11.0.10008.0 pour Microsoft Exchange Server
    ESET Security ESET Security versions antérieures à 11.0.15004.0 pour Microsoft SharePoint Server
    ESET Server Security ESET Server Security versions antérieures à 11.0.12012.0 pour Windows Server
    ESET Endpoint Antivirus ESET Endpoint Antivirus versions antérieures à 11.1.2039.0 pour Windows
    ESET Security Ultimate ESET Security Ultimate versions antérieures à 17.2.7.0
    ESET Internet Security ESET Internet Security versions antérieures à 17.2.7.0
    ESET Endpoint Security ESET Endpoint Security versions antérieures à 11.1.2039.0 pour Windows
    ESET NOD32 Antivirus ESET NOD32 Antivirus versions antérieures à 17.2.7.0
    References
    Bulletin de sécurité ESET ca8688 2024-07-12 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "ESET Smart Security Premium versions ant\u00e9rieures \u00e0 17.2.7.0",
          "product": {
            "name": "Smart Security Premium",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Mail Security versions ant\u00e9rieures \u00e0 11.0.10008.0 pour Microsoft Exchange Server",
          "product": {
            "name": "Mail Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Security versions ant\u00e9rieures \u00e0 11.0.15004.0 pour Microsoft SharePoint Server",
          "product": {
            "name": "Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Server Security versions ant\u00e9rieures \u00e0 11.0.12012.0 pour Windows Server",
          "product": {
            "name": "Server Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Endpoint Antivirus versions ant\u00e9rieures \u00e0 11.1.2039.0 pour Windows",
          "product": {
            "name": "Endpoint Antivirus",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Security Ultimate versions ant\u00e9rieures \u00e0 17.2.7.0",
          "product": {
            "name": "Security Ultimate",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": " ESET Internet Security versions ant\u00e9rieures \u00e0 17.2.7.0",
          "product": {
            "name": "Internet Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Endpoint Security versions ant\u00e9rieures \u00e0 11.1.2039.0 pour Windows",
          "product": {
            "name": "Endpoint Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET NOD32 Antivirus versions ant\u00e9rieures \u00e0 17.2.7.0",
          "product": {
            "name": "NOD32 Antivirus",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2024-3779",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-3779"
        }
      ],
      "initial_release_date": "2024-07-15T00:00:00",
      "last_revision_date": "2024-07-15T00:00:00",
      "links": [],
      "reference": "CERTFR-2024-AVI-0581",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2024-07-15T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
        },
        {
          "description": "D\u00e9ni de service"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans les produits ESET. Elle permet \u00e0 un attaquant de provoquer une atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es et un d\u00e9ni de service.",
      "title": "Vuln\u00e9rabilit\u00e9 dans les produits ESET",
      "vendor_advisories": [
        {
          "published_at": "2024-07-12",
          "title": "Bulletin de s\u00e9curit\u00e9 ESET ca8688",
          "url": "https://support-feed.eset.com/link/15370/16741922/ca8688"
        }
      ]
    }

    CERTFR-2024-AVI-0136

    Vulnerability from certfr_avis - Published: 2024-02-15 - Updated: 2024-02-15

    Une vulnérabilité a été découverte dans les produits ESET. Elle permet à un attaquant de provoquer une élévation de privilèges.

    Solution

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    None
    Impacted products
    Vendor Product Description
    ESET Security ESET Security pour Microsoft SharePoint Server versions 7.3.x.x antérieures à 7.3.15006.0
    ESET N/A ESET NOD32 Antivirus, ESET Internet Security, ESET Smart Security Premium et ESET Security Ultimate versions antérieures à 17.0.10.0
    ESET Mail Security ESET Mail Security pour IBM Domino versions 10.0.x.x antérieures à 10.0.14007.0
    ESET Mail Security ESET Mail Security pour Microsoft Exchange Server versions 10.1.x.x antérieures à 10.1.10014.0
    ESET Security ESET Security pour Microsoft SharePoint Server versions 9.0.x.x antérieures à 9.0.15006.0
    ESET Mail Security ESET Mail Security pour IBM Domino versions 7.3.x.x antérieures à 7.3.14006.0
    ESET N/A ESET Server Security pour Windows Server (anciennement File Security pour Microsoft Windows Server) versions 10.0.x.x antérieures à 10.0.12015.0
    ESET Mail Security ESET Mail Security pour IBM Domino versions 8.0.x.x antérieures à 8.0.14014.0
    ESET N/A ESET Endpoint Antivirus pour Windows et ESET Endpoint Security pour Windows versions 10.1.x.x antérieures à 10.1.2063.0
    ESET N/A ESET Endpoint Antivirus pour Windows et ESET Endpoint Security pour Windows versions 10.0.x.x antérieures à 10.0.2052.0
    ESET N/A ESET Server Security pour Windows Server (anciennement File Security pour Microsoft Windows Server) versions 7.3.x.x antérieures à 7.3.12013.0
    ESET N/A ESET Endpoint Antivirus pour Windows et ESET Endpoint Security pour Windows versions 8.1.x.x antérieures à 8.1.2062.0
    ESET Mail Security ESET Mail Security pour Microsoft Exchange Server versions 9.0.x.x antérieures à 9.0.10012.0
    ESET N/A ESET Server Security pour Windows Server (anciennement File Security pour Microsoft Windows Server) versions 8.0.x.x antérieures à 8.0.12016.0
    ESET Mail Security ESET Mail Security pour Microsoft Exchange Server versions 8.0.x.x antérieures à 8.0.10024.0
    ESET Mail Security ESET Mail Security pour Microsoft Exchange Server versions 7.3.x.x antérieures à 7.3.10018.0
    ESET Security ESET Security pour Microsoft SharePoint Server versions 8.0.x.x antérieures à 8.0.15012.0
    ESET Security ESET Security pour Microsoft SharePoint Server versions 10.0.x.x antérieures à 10.0.15005.0
    ESET Mail Security ESET Mail Security pour Microsoft Exchange Server versions 10.0.x.x antérieures à 10.0.10018.0
    ESET N/A ESET Endpoint Antivirus pour Windows et ESET Endpoint Security pour Windows versions 9.1.x.x antérieures à 9.1.2071.0
    ESET Mail Security ESET Mail Security pour IBM Domino versions 9.0.x.x antérieures à 9.0.14008.0
    ESET N/A ESET Server Security pour Windows Server (anciennement File Security pour Microsoft Windows Server) versions 9.0.x.x antérieures à 9.0.12019.0
    ESET N/A ESET Endpoint Antivirus pour Windows et ESET Endpoint Security pour Windows versions 11.0.x.x antérieures à 11.0.2032.0
    ESET File Security ESET File Security pour Microsoft Azure

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "ESET Security pour Microsoft SharePoint Server versions 7.3.x.x ant\u00e9rieures \u00e0 7.3.15006.0",
          "product": {
            "name": "Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET NOD32 Antivirus, ESET Internet Security, ESET Smart Security Premium et ESET Security Ultimate versions ant\u00e9rieures \u00e0 17.0.10.0",
          "product": {
            "name": "N/A",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Mail Security pour IBM Domino versions 10.0.x.x ant\u00e9rieures \u00e0 10.0.14007.0",
          "product": {
            "name": "Mail Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Mail Security pour Microsoft Exchange Server versions 10.1.x.x ant\u00e9rieures \u00e0 10.1.10014.0",
          "product": {
            "name": "Mail Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Security pour Microsoft SharePoint Server versions 9.0.x.x ant\u00e9rieures \u00e0 9.0.15006.0",
          "product": {
            "name": "Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Mail Security pour IBM Domino versions 7.3.x.x ant\u00e9rieures \u00e0 7.3.14006.0",
          "product": {
            "name": "Mail Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Server Security pour Windows Server (anciennement File Security pour Microsoft Windows Server) versions 10.0.x.x ant\u00e9rieures \u00e0 10.0.12015.0",
          "product": {
            "name": "N/A",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Mail Security pour IBM Domino versions 8.0.x.x ant\u00e9rieures \u00e0 8.0.14014.0",
          "product": {
            "name": "Mail Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Endpoint Antivirus pour Windows et ESET Endpoint Security pour Windows versions 10.1.x.x ant\u00e9rieures \u00e0 10.1.2063.0",
          "product": {
            "name": "N/A",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Endpoint Antivirus pour Windows et ESET Endpoint Security pour Windows versions 10.0.x.x ant\u00e9rieures \u00e0 10.0.2052.0",
          "product": {
            "name": "N/A",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Server Security pour Windows Server (anciennement File Security pour Microsoft Windows Server) versions 7.3.x.x ant\u00e9rieures \u00e0 7.3.12013.0",
          "product": {
            "name": "N/A",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Endpoint Antivirus pour Windows et ESET Endpoint Security pour Windows versions 8.1.x.x ant\u00e9rieures \u00e0 8.1.2062.0",
          "product": {
            "name": "N/A",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Mail Security pour Microsoft Exchange Server versions 9.0.x.x ant\u00e9rieures \u00e0 9.0.10012.0",
          "product": {
            "name": "Mail Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Server Security pour Windows Server (anciennement File Security pour Microsoft Windows Server) versions 8.0.x.x ant\u00e9rieures \u00e0 8.0.12016.0",
          "product": {
            "name": "N/A",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Mail Security pour Microsoft Exchange Server versions 8.0.x.x ant\u00e9rieures \u00e0 8.0.10024.0",
          "product": {
            "name": "Mail Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Mail Security pour Microsoft Exchange Server versions 7.3.x.x ant\u00e9rieures \u00e0 7.3.10018.0",
          "product": {
            "name": "Mail Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Security pour Microsoft SharePoint Server versions 8.0.x.x ant\u00e9rieures \u00e0 8.0.15012.0",
          "product": {
            "name": "Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Security pour Microsoft SharePoint Server versions 10.0.x.x ant\u00e9rieures \u00e0 10.0.15005.0",
          "product": {
            "name": "Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Mail Security pour Microsoft Exchange Server versions 10.0.x.x ant\u00e9rieures \u00e0 10.0.10018.0",
          "product": {
            "name": "Mail Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Endpoint Antivirus pour Windows et ESET Endpoint Security pour Windows versions 9.1.x.x ant\u00e9rieures \u00e0 9.1.2071.0",
          "product": {
            "name": "N/A",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Mail Security pour IBM Domino versions 9.0.x.x ant\u00e9rieures \u00e0 9.0.14008.0",
          "product": {
            "name": "Mail Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Server Security pour Windows Server (anciennement File Security pour Microsoft Windows Server) versions 9.0.x.x ant\u00e9rieures \u00e0 9.0.12019.0",
          "product": {
            "name": "N/A",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Endpoint Antivirus pour Windows et ESET Endpoint Security pour Windows versions 11.0.x.x ant\u00e9rieures \u00e0 11.0.2032.0",
          "product": {
            "name": "N/A",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET File Security pour Microsoft Azure",
          "product": {
            "name": "File Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": null,
      "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
      "cves": [
        {
          "name": "CVE-2024-0353",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-0353"
        }
      ],
      "initial_release_date": "2024-02-15T00:00:00",
      "last_revision_date": "2024-02-15T00:00:00",
      "links": [
        {
          "title": "Bulletin de s\u00e9curit\u00e9 ESET\u00a0CA8612 du 14 f\u00e9vrier 2024",
          "url": "https://support.eset.com/en/ca8612-eset-customer-advisory-link-following-local-privilege-escalation-vulnerability-in-eset-products-for-windows-fixed"
        }
      ],
      "reference": "CERTFR-2024-AVI-0136",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2024-02-15T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "\u00c9l\u00e9vation de privil\u00e8ges"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans \u003cspan class=\"textit\"\u003eles\nproduits ESET\u003c/span\u003e. Elle permet \u00e0 un attaquant de provoquer une\n\u00e9l\u00e9vation de privil\u00e8ges.\n",
      "title": "Vuln\u00e9rabilit\u00e9 dans les produits ESET",
      "vendor_advisories": [
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 ESET CA8612 du 14 f\u00e9vrier 2024",
          "url": null
        }
      ]
    }

    CERTFR-2024-AVI-0079

    Vulnerability from certfr_avis - Published: 2024-01-30 - Updated: 2024-01-30

    Une vulnérabilité a été découverte dans les produits ESET. Elle permet à un attaquant de provoquer une exécution de code arbitraire.

    Solution

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    None
    Impacted products
    Vendor Product Description
    ESET N/A ESET Endpoint Security et ESET Endpoint Antivirus versions antérieures à 11.0.2032.x
    ESET Mail Security ESET Mail Security pour Microsoft Exchange Server versions antérieures à 10.1.10014.0
    ESET N/A ESET NOD32 Antivirus, ESET Internet Security et ESET Smart Security Premium versions antérieures à 17.0.15.0
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "ESET Endpoint Security et ESET Endpoint Antivirus versions ant\u00e9rieures \u00e0 11.0.2032.x",
          "product": {
            "name": "N/A",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Mail Security pour Microsoft Exchange Server versions ant\u00e9rieures \u00e0 10.1.10014.0",
          "product": {
            "name": "Mail Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET NOD32 Antivirus, ESET Internet Security et ESET Smart Security Premium versions ant\u00e9rieures \u00e0 17.0.15.0",
          "product": {
            "name": "N/A",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": null,
      "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
      "cves": [
        {
          "name": "CVE-2023-7043",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-7043"
        }
      ],
      "initial_release_date": "2024-01-30T00:00:00",
      "last_revision_date": "2024-01-30T00:00:00",
      "links": [],
      "reference": "CERTFR-2024-AVI-0079",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2024-01-30T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Ex\u00e9cution de code arbitraire"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans \u003cspan class=\"textit\"\u003eles\nproduits ESET\u003c/span\u003e. Elle permet \u00e0 un attaquant de provoquer une\nex\u00e9cution de code arbitraire.\n",
      "title": "Vuln\u00e9rabilit\u00e9 dans les produits ESET",
      "vendor_advisories": [
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 ESET CA8602 du 26 janvier 2024",
          "url": "https://support.eset.com/en/ca8602-eset-customer-advisory-unquoted-path-privilege-vulnerability-in-eset-products-for-windows-fixed"
        }
      ]
    }

    CERTFR-2023-AVI-1053

    Vulnerability from certfr_avis - Published: 2023-12-22 - Updated: 2023-12-22

    Une vulnérabilité a été découverte dans les produits ESET. Elle permet à un attaquant de provoquer une atteinte à la confidentialité des données et un contournement de la politique de sécurité.

    Solution

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    None
    Impacted products
    Vendor Product Description
    ESET Security Ultimate ESET Security Ultimate
    ESET Endpoint Antivirus ESET Endpoint Antivirus versions postérieures à 10.0 pour Linux
    ESET Server Security ESET Server Security versions postérieures à 10.1 pour Linux
    ESET Endpoint Antivirus ESET Endpoint Antivirus pour Windows
    ESET NOD32 Antivirus ESET NOD32 Antivirus
    ESET Endpoint Security ESET Endpoint Security pour Windows
    ESET Smart Security Premium ESET Smart Security Premium
    ESET Mail Security ESET Mail Security pour Microsoft Exchange Server
    ESET Internet Security ESET Internet Security
    ESET Server Security ESET Server Security pour Windows Server
    ESET Mail Security ESET Mail Security pour IBM Domino
    ESET Security ESET Security pour Microsoft SharePoint Server
    ESET File Security ESET File Security pour Microsoft Azure

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "ESET Security Ultimate",
          "product": {
            "name": "Security Ultimate",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Endpoint Antivirus versions post\u00e9rieures \u00e0 10.0 pour Linux",
          "product": {
            "name": "Endpoint Antivirus",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Server Security versions post\u00e9rieures \u00e0 10.1 pour Linux",
          "product": {
            "name": "Server Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Endpoint Antivirus pour Windows",
          "product": {
            "name": "Endpoint Antivirus",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET NOD32 Antivirus",
          "product": {
            "name": "NOD32 Antivirus",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Endpoint Security pour Windows",
          "product": {
            "name": "Endpoint Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Smart Security Premium",
          "product": {
            "name": "Smart Security Premium",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Mail Security pour Microsoft Exchange Server",
          "product": {
            "name": "Mail Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Internet Security",
          "product": {
            "name": "Internet Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Server Security pour Windows Server",
          "product": {
            "name": "Server Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Mail Security pour IBM Domino",
          "product": {
            "name": "Mail Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET Security pour Microsoft SharePoint Server",
          "product": {
            "name": "Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "ESET File Security pour Microsoft Azure",
          "product": {
            "name": "File Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": null,
      "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
      "cves": [
        {
          "name": "CVE-2023-5594",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-5594"
        }
      ],
      "initial_release_date": "2023-12-22T00:00:00",
      "last_revision_date": "2023-12-22T00:00:00",
      "links": [
        {
          "title": "Bulletin de s\u00e9curit\u00e9 ESET\u00a0CA8562 du 20 d\u00e9cembre 2023",
          "url": "https://support.eset.com/en/ca8562-eset-customer-advisory-improper-following-of-a-certificates-chain-of-trust-in-eset-security-products-fixed"
        }
      ],
      "reference": "CERTFR-2023-AVI-1053",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2023-12-22T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans \u003cspan class=\"textit\"\u003eles\nproduits ESET\u003c/span\u003e. Elle permet \u00e0 un attaquant de provoquer une\natteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es et un contournement de la\npolitique de s\u00e9curit\u00e9.\n",
      "title": "Vuln\u00e9rabilit\u00e9 dans les produits ESET",
      "vendor_advisories": [
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 ESET CA8562 du 20 d\u00e9cembre 2023",
          "url": null
        }
      ]
    }

    CERTFR-2023-AVI-0764

    Vulnerability from certfr_avis - Published: 2023-09-20 - Updated: 2023-09-20

    Une vulnérabilité a été découverte dans les produits TrendMicro. Elle permet à un attaquant de provoquer une exécution de code arbitraire.

    Solution

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    None
    Impacted products
    Vendor Product Description
    ESET Security TrendMicro Worry-Free Business Security en mode SaaS (WFBSS) sans le correctif mensuel de maintenance du 31 juillet 2023
    Trend Micro Apex One TrendMicro Apex One versions 2019 (On-prem) sans le correctif de sécurité SP1 Patch 1 (B12380)
    Trend Micro Apex One TrendMicro Apex One en mode SaaS sans le correctif mensuel de sécurité du mois de juillet 2023 (202307)
    ESET Security TrendMicro Worry-Free Business Security (WFBS) version 10.0 SP1 sans le correctif de sécurité SP1 Patch 2495

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "TrendMicro Worry-Free Business Security en mode SaaS (WFBSS) sans le correctif mensuel de maintenance du 31 juillet 2023",
          "product": {
            "name": "Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        },
        {
          "description": "TrendMicro Apex One versions 2019 (On-prem) sans le correctif de s\u00e9curit\u00e9 SP1 Patch 1 (B12380)",
          "product": {
            "name": "Apex One",
            "vendor": {
              "name": "Trend Micro",
              "scada": false
            }
          }
        },
        {
          "description": "TrendMicro Apex One en mode SaaS sans le correctif mensuel de s\u00e9curit\u00e9 du mois de juillet 2023 (202307)",
          "product": {
            "name": "Apex One",
            "vendor": {
              "name": "Trend Micro",
              "scada": false
            }
          }
        },
        {
          "description": "TrendMicro Worry-Free Business Security (WFBS) version 10.0 SP1 sans le correctif de s\u00e9curit\u00e9 SP1 Patch 2495",
          "product": {
            "name": "Security",
            "vendor": {
              "name": "ESET",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": null,
      "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
      "cves": [
        {
          "name": "CVE-2023-41179",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-41179"
        }
      ],
      "initial_release_date": "2023-09-20T00:00:00",
      "last_revision_date": "2023-09-20T00:00:00",
      "links": [
        {
          "title": "Bulletin de s\u00e9curit\u00e9 TrendMicro\u00a0000294994 du 19 septembre 2023",
          "url": "https://success.trendmicro.com/dcx/s/solution/000294994?language=en_US"
        }
      ],
      "reference": "CERTFR-2023-AVI-0764",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2023-09-20T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Ex\u00e9cution de code arbitraire"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans \u003cspan class=\"textit\"\u003eles\nproduits TrendMicro\u003c/span\u003e. Elle permet \u00e0 un attaquant de provoquer une\nex\u00e9cution de code arbitraire.\n",
      "title": "Vuln\u00e9rabilit\u00e9 dans les produits TrendMicro",
      "vendor_advisories": [
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 TrendMicro 000294994 du 19 septembre 2023",
          "url": null
        }
      ]
    }

    CVE-2025-13818 (GCVE-0-2025-13818)

    Vulnerability from nvd – Published: 2026-02-06 13:13 – Updated: 2026-02-06 14:25
    VLAI
    Title
    Local privilege escalation in ESET Management Agent for Windows
    Summary
    Local privilege escalation vulnerability via insecure temporary batch file execution in ESET Management Agent
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-02-06 14:23 UTC
    CWE
    • CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition
    Impacted products
    Vendor Product Version
    ESET spol s.r.o. ESET Management Agent Affected: 0 , ≤ 12.5.2104.0 (custom)
    Create a notification for this product.
    Date Public
    2026-02-06 11:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-13818",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-02-06T14:23:49.218691Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-02-06T14:25:02.493Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "Windows"
              ],
              "product": "ESET Management Agent",
              "vendor": "ESET spol s.r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "12.5.2104.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2026-02-06T11:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Local privilege escalation vulnerability via insecure temporary batch file execution in ESET Management Agent"
                }
              ],
              "value": "Local privilege escalation vulnerability via insecure temporary batch file execution in ESET Management Agent"
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-233",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-233 Privilege Escalation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "LOCAL",
                "baseScore": 8.3,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "HIGH",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-367",
                  "description": "CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-02-06T13:13:47.046Z",
            "orgId": "4a9b9929-2450-4021-b7b9-469a0255b215",
            "shortName": "ESET"
          },
          "references": [
            {
              "url": "https://support.eset.com/en/ca8913-eset-customer-advisory-local-privilege-escalation-via-insecure-temporary-batch-file-execution-in-eset-management-agent-for-windows-fixed"
            }
          ],
          "source": {
            "advisory": "ca8913",
            "discovery": "UNKNOWN"
          },
          "title": "Local privilege escalation in ESET Management Agent for Windows",
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4a9b9929-2450-4021-b7b9-469a0255b215",
        "assignerShortName": "ESET",
        "cveId": "CVE-2025-13818",
        "datePublished": "2026-02-06T13:13:47.046Z",
        "dateReserved": "2025-12-01T07:56:48.667Z",
        "dateUpdated": "2026-02-06T14:25:02.493Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-4952 (GCVE-0-2025-4952)

    Vulnerability from nvd – Published: 2025-10-31 12:28 – Updated: 2025-10-31 14:18
    VLAI
    Title
    Denial-of-service vulnerability in ESET security products for Windows
    Summary
    Tampering of the registry entries might have led to preventing the ESET security products from starting correctly on the next system startup or to unauthorized changes in the product's configuration.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-10-31 14:18 UTC
    CWE
    • CWE-732 - Incorrect Permission Assignment for Critical Resource
    Date Public
    2025-08-22 10:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-4952",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-10-31T14:18:06.194469Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-10-31T14:18:16.911Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "hips"
              ],
              "platforms": [
                "Windows"
              ],
              "product": "ESET NOD32 Antivirus",
              "vendor": "ESET",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1496",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "HIPS support module"
              ],
              "product": "ESET Internet Security",
              "vendor": "ESET",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1496"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "HIPS support module"
              ],
              "product": "ESET Smart Security Premium",
              "vendor": "ESET",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1496"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "HIPS support module"
              ],
              "product": "ESET Security Ultimate",
              "vendor": "ESET",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1496",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "HIPS support module"
              ],
              "product": "ESET Small Business Security",
              "vendor": "ESET",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1496",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "HIPS support module"
              ],
              "product": "ESET Safe Server",
              "vendor": "ESET",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1496",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "HIPS support module"
              ],
              "product": "ESET Endpoint Antivirus",
              "vendor": "ESET",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1496",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "HIPS support module"
              ],
              "product": "ESET Endpoint Security for Windows",
              "vendor": "ESET",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1496",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "HIPS support module"
              ],
              "product": "ESET Server Security for Windows Server",
              "vendor": "ESET",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1496",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "HIPS support module"
              ],
              "product": "ESET Mail Security for Microsoft Exchange Server",
              "vendor": "ESET",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1496",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "HIPS support module"
              ],
              "product": "ESET Mail Security for IBM Domino",
              "vendor": "ESET",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1496",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "HIPS support module"
              ],
              "product": "ESET Security for Microsoft SharePoint Server",
              "vendor": "ESET",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1496",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "HIPS support module"
              ],
              "product": "ESET File Security for Microsoft Azure",
              "vendor": "ESET",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1496",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:eset:eset_nod32_antivirus:1496:*:windows:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                },
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:eset:eset_internet_security:1496:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                },
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:eset:eset_smart_security_premium:1496:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                },
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:eset:eset_security_ultimate:1496:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                },
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:eset:eset_small_business_security:1496:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                },
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:eset:eset_safe_server:1496:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                },
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:eset:eset_endpoint_antivirus:1496:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                },
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:eset:eset_endpoint_security_for_windows:1496:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                },
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:eset:eset_server_security_for_windows_server:1496:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                },
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:eset:eset_mail_security_for_microsoft_exchange_server:1496:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                },
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:eset:eset_mail_security_for_ibm_domino:1496:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                },
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:eset:eset_security_for_microsoft_sharepoint_server:1496:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                },
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:eset:eset_file_security_for_microsoft_azure:1496:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "datePublic": "2025-08-22T10:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eTampering of the registry entries might have led to preventing the ESET security products from starting correctly on the next system startup or to unauthorized changes in the product\u0027s configuration.\u003c/span\u003e"
                }
              ],
              "value": "Tampering of the registry entries might have led to preventing the ESET security products from starting correctly on the next system startup or to unauthorized changes in the product\u0027s configuration."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-203",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-203 Manipulate Registry Information"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "LOCAL",
                "baseScore": 6.8,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "HIGH",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-732",
                  "description": "CWE-732 Incorrect Permission Assignment for Critical Resource",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-10-31T12:28:15.267Z",
            "orgId": "4a9b9929-2450-4021-b7b9-469a0255b215",
            "shortName": "ESET"
          },
          "references": [
            {
              "url": "https://support.eset.com/en/ca8853-eset-customer-advisory-denial-of-service-vulnerability-in-eset-security-products-for-windows-fixed"
            }
          ],
          "source": {
            "advisory": "ca8853",
            "discovery": "UNKNOWN"
          },
          "title": "Denial-of-service vulnerability in ESET security products for Windows",
          "x_generator": {
            "engine": "Vulnogram 0.4.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4a9b9929-2450-4021-b7b9-469a0255b215",
        "assignerShortName": "ESET",
        "cveId": "CVE-2025-4952",
        "datePublished": "2025-10-31T12:28:15.267Z",
        "dateReserved": "2025-05-19T10:36:38.958Z",
        "dateUpdated": "2025-10-31T14:18:16.911Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-7400 (GCVE-0-2024-7400)

    Vulnerability from nvd – Published: 2024-09-27 07:02 – Updated: 2024-09-27 18:54
    VLAI
    Title
    Local privilege escalation in ESET products for Windows
    Summary
    The vulnerability potentially allowed an attacker to misuse ESET’s file operations during the removal of a detected file on the Windows operating system to delete files without having proper permissions to do so.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-27 17:57 UTC
    CWE
    • CWE-1386 - Insecure Operation on Windows Junction / Mount Point
    Impacted products
    Vendor Product Version
    ESET, spol. s r.o. ESET NOD32 Antivirus Affected: 0 , ≤ 1250 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Internet Security Affected: 0 , ≤ 1250 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Smart Security Premium Affected: 0 , ≤ 1250 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Security Ultimate Affected: 0 , ≤ 1250 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Small Business Security Affected: 0 , ≤ 1250 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Safe Server Affected: 0 , ≤ 1250 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Endpoint Antivirus Affected: 0 , ≤ 1250 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Endpoint Security for Windows Affected: 0 , ≤ 1250 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Server Security for Windows Server Affected: 0 , ≤ 1250 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Mail Security for Microsoft Exchange Server Affected: 0 , ≤ 1250 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Mail Security for IBM Domino Affected: 0 , ≤ 1250 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Security for Microsoft SharePoint Server Affected: 0 , ≤ 1250 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET File Security for Microsoft Azure Affected: 0 , ≤ 1250 (custom)
    Create a notification for this product.
    eset mail_security Affected: 0 , ≤ 1250 (custom)
        cpe:2.3:a:eset:security:-:*:*:*:*:sharepoint_server:*:*
        cpe:2.3:a:eset:safe_server:-:*:*:*:*:*:*:*
        cpe:2.3:a:eset:security_ultimate:*:*:*:*:*:*:*:*
        cpe:2.3:a:eset:server_security:-:*:*:*:*:windows_server:*:*
        cpe:2.3:a:eset:small_business_security:*:*:*:*:*:*:*:*
        cpe:2.3:a:eset:smart_security:-:*:*:*:premium:*:*:*
        cpe:2.3:a:eset:nod32_antivirus:*:*:*:*:*:*:*:*
        cpe:2.3:a:eset:endpoint_antivirus:*:*:*:*:*:*:*:*
        cpe:2.3:a:eset:endpoint_security:-:*:*:*:*:windows:*:*
        cpe:2.3:a:eset:file_security:-:*:*:*:*:azure:*:*
        cpe:2.3:a:eset:internet_security:*:*:*:*:*:*:*:*
        cpe:2.3:a:eset:mail_security:-:*:*:*:*:domino:*:*
        cpe:2.3:a:eset:mail_security:-:*:*:*:*:exchange_server:*:*
    Create a notification for this product.
    Date Public
    2024-09-20 10:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:eset:security:-:*:*:*:*:sharepoint_server:*:*",
                  "cpe:2.3:a:eset:safe_server:-:*:*:*:*:*:*:*",
                  "cpe:2.3:a:eset:security_ultimate:*:*:*:*:*:*:*:*",
                  "cpe:2.3:a:eset:server_security:-:*:*:*:*:windows_server:*:*",
                  "cpe:2.3:a:eset:small_business_security:*:*:*:*:*:*:*:*",
                  "cpe:2.3:a:eset:smart_security:-:*:*:*:premium:*:*:*",
                  "cpe:2.3:a:eset:nod32_antivirus:*:*:*:*:*:*:*:*",
                  "cpe:2.3:a:eset:endpoint_antivirus:*:*:*:*:*:*:*:*",
                  "cpe:2.3:a:eset:endpoint_security:-:*:*:*:*:windows:*:*",
                  "cpe:2.3:a:eset:file_security:-:*:*:*:*:azure:*:*",
                  "cpe:2.3:a:eset:internet_security:*:*:*:*:*:*:*:*",
                  "cpe:2.3:a:eset:mail_security:-:*:*:*:*:domino:*:*",
                  "cpe:2.3:a:eset:mail_security:-:*:*:*:*:exchange_server:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "mail_security",
                "vendor": "eset",
                "versions": [
                  {
                    "lessThanOrEqual": "1250",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-7400",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-27T17:57:43.358687Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-27T18:54:39.099Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Cleaner module"
              ],
              "product": "ESET NOD32 Antivirus",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "1250",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Cleaner module"
              ],
              "product": "ESET Internet Security",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "1250",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Cleaner module"
              ],
              "product": "ESET Smart Security Premium",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "1250",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Cleaner module"
              ],
              "product": "ESET Security Ultimate",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "1250",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Cleaner module"
              ],
              "product": "ESET Small Business Security",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "1250",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Cleaner module"
              ],
              "product": "ESET Safe Server",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "1250",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Cleaner module"
              ],
              "product": "ESET Endpoint Antivirus",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "1250",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Cleaner module"
              ],
              "product": "ESET Endpoint Security for Windows",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "1250",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Cleaner module"
              ],
              "product": "ESET Server Security for Windows Server",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "1250",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Cleaner module"
              ],
              "product": "ESET Mail Security for Microsoft Exchange Server",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "1250",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Cleaner module"
              ],
              "product": "ESET Mail Security for IBM Domino",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "1250",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Cleaner module"
              ],
              "product": "ESET Security for Microsoft SharePoint Server",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "1250",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Cleaner module"
              ],
              "product": "ESET File Security for Microsoft Azure",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "1250",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2024-09-20T10:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eThe vulnerability potentially allowed an attacker to misuse ESET\u2019s file operations during the removal of a detected file on the Windows operating system to delete files without having proper permissions to do so.\u003c/span\u003e"
                }
              ],
              "value": "The vulnerability potentially allowed an attacker to misuse ESET\u2019s file operations during the removal of a detected file on the Windows operating system to delete files without having proper permissions to do so."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-233",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-233 Privilege Escalation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "LOCAL",
                "baseScore": 8.5,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-1386",
                  "description": "CWE-1386 Insecure Operation on Windows Junction / Mount Point",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-09-27T07:02:28.931Z",
            "orgId": "4a9b9929-2450-4021-b7b9-469a0255b215",
            "shortName": "ESET"
          },
          "references": [
            {
              "url": "https://support.eset.com/en/ca8726-local-privilege-escalation-fixed-for-vulnerability-during-detected-file-removal-in-eset-products-for-windows"
            }
          ],
          "source": {
            "advisory": "ca8726",
            "discovery": "UNKNOWN"
          },
          "title": "Local privilege escalation in ESET products for Windows",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4a9b9929-2450-4021-b7b9-469a0255b215",
        "assignerShortName": "ESET",
        "cveId": "CVE-2024-7400",
        "datePublished": "2024-09-27T07:02:28.931Z",
        "dateReserved": "2024-08-02T07:12:41.358Z",
        "dateUpdated": "2024-09-27T18:54:39.099Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-3779 (GCVE-0-2024-3779)

    Vulnerability from nvd – Published: 2024-07-16 08:17 – Updated: 2024-08-01 20:20
    VLAI
    Title
    Denial of Service in ESET products for Windows
    Summary
    Denial of service vulnerability present shortly after product installation or upgrade, potentially allowed an attacker to render ESET’s security product inoperable, provided non-default preconditions were met.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-07-16 13:10 UTC
    CWE
    • CWE-276 - Incorrect Default Permissions
    References
    Date Public
    2024-07-12 10:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-3779",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-07-16T13:10:29.360811Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-07-16T13:10:35.421Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T20:20:01.654Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://support.eset.com/en/ca8688"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ESET NOD32 Antivirus",
              "vendor": "ESET s.r.o",
              "versions": [
                {
                  "lessThanOrEqual": "17.1.13.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Internet Security",
              "vendor": "ESET s.r.o",
              "versions": [
                {
                  "lessThanOrEqual": "17.1.13.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Smart Security Premium",
              "vendor": "ESET s.r.o",
              "versions": [
                {
                  "lessThanOrEqual": "17.1.13.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Security Ultimate",
              "vendor": "ESET s.r.o",
              "versions": [
                {
                  "lessThanOrEqual": "17.1.13.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Endpoint Antivirus for Windows",
              "vendor": "ESET s.r.o",
              "versions": [
                {
                  "lessThanOrEqual": "11.0.2044.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Endpoint Security for Windows",
              "vendor": "ESET s.r.o",
              "versions": [
                {
                  "lessThanOrEqual": "11.0.2044.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Server Security for Windows Server",
              "vendor": "ESET s.r.o",
              "versions": [
                {
                  "lessThanOrEqual": "11.0.12011.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Mail Security for Microsoft Exchange Server",
              "vendor": "ESET s.r.o",
              "versions": [
                {
                  "lessThanOrEqual": "11.0.10005.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Mail Security for IBM Domino",
              "vendor": "ESET s.r.o",
              "versions": [
                {
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Security for Microsoft SharePoint Server",
              "vendor": "ESET s.r.o",
              "versions": [
                {
                  "lessThanOrEqual": "11.0.15002.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2024-07-12T10:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Denial of service vulnerability present shortly after product installation or upgrade, potentially allowed an attacker to render ESET\u2019s security product inoperable, provided non-default preconditions were met."
                }
              ],
              "value": "Denial of service vulnerability present shortly after product installation or upgrade, potentially allowed an attacker to render ESET\u2019s security product inoperable, provided non-default preconditions were met."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-578",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-578 Disable Security Software"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 6.1,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-276",
                  "description": "CWE-276 Incorrect Default Permissions",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-07-16T08:17:59.962Z",
            "orgId": "4a9b9929-2450-4021-b7b9-469a0255b215",
            "shortName": "ESET"
          },
          "references": [
            {
              "url": "https://support.eset.com/en/ca8688"
            }
          ],
          "source": {
            "advisory": "ca8688",
            "discovery": "UNKNOWN"
          },
          "title": "Denial of Service in ESET products for Windows",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4a9b9929-2450-4021-b7b9-469a0255b215",
        "assignerShortName": "ESET",
        "cveId": "CVE-2024-3779",
        "datePublished": "2024-07-16T08:17:59.962Z",
        "dateReserved": "2024-04-15T07:03:57.841Z",
        "dateUpdated": "2024-08-01T20:20:01.654Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-2003 (GCVE-0-2024-2003)

    Vulnerability from nvd – Published: 2024-06-21 07:20 – Updated: 2024-08-01 18:56
    VLAI
    Title
    Local Privilege Escalation in Quarantine of ESET products for Windows
    Summary
    Local privilege escalation vulnerability allowed an attacker to misuse ESET's file operations during a restore operation from quarantine.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-21 14:03 UTC
    CWE
    • CWE-269 - Improper Privilege Management
    References
    Impacted products
    Vendor Product Version
    ESET, spol. s r.o. ESET NOD32 Antivirus Affected: 0 , < 1610 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Internet Security Affected: 0 , < 1610 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Smart Security Premium Affected: 0 , < 1610 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Security Ultimate Affected: 0 , < 1610 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Small Business Security Affected: 0 , < 1610 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Safe Server Affected: 0 , < 1610 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Endpoint Antivirus for Windows Affected: 0 , < 1610 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Endpoint Security for Windows Affected: 0 , < 1610 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Server Security for Windows Server Affected: 0 , < 1610 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Mail Security for Microsoft Exchange Server Affected: 0 , < 1610 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Mail Security for IBM Domino Affected: 0 , < 1610 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Security for Microsoft SharePoint Server Affected: 0 , < 1610 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET File Security for Microsoft Azure Affected: 0 , < 1610 (custom)
    Create a notification for this product.
    eset internet_security Affected: 0 , < 1610 (custom)
        cpe:2.3:a:eset:safe_server:-:*:*:*:*:*:*:*
        cpe:2.3:a:eset:file_security:-:*:*:*:*:azure:*:*
        cpe:2.3:a:eset:security:-:*:*:*:*:sharepoint_server:*:*
        cpe:2.3:a:eset:mail_security:-:*:*:*:*:domino:*:*
        cpe:2.3:a:eset:server_security:-:*:*:*:*:windows_server:*:*
        cpe:2.3:a:eset:endpoint_security:-:*:*:*:*:windows:*:*
        cpe:2.3:a:eset:endpoint_antivirus:-:*:*:*:*:windows:*:*
        cpe:2.3:a:eset:smart_security:-:*:*:*:business:*:*:*
        cpe:2.3:a:eset:security:-:*:*:*:ultimate:*:*:*
        cpe:2.3:a:eset:smart_security:-:*:*:*:premium:*:*:*
        cpe:2.3:a:eset:nod32:-:-:*:*:*:*:*:*
        cpe:2.3:a:eset:internet_security:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-06-20 10:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:eset:safe_server:-:*:*:*:*:*:*:*",
                  "cpe:2.3:a:eset:file_security:-:*:*:*:*:azure:*:*",
                  "cpe:2.3:a:eset:security:-:*:*:*:*:sharepoint_server:*:*",
                  "cpe:2.3:a:eset:mail_security:-:*:*:*:*:domino:*:*",
                  "cpe:2.3:a:eset:server_security:-:*:*:*:*:windows_server:*:*",
                  "cpe:2.3:a:eset:endpoint_security:-:*:*:*:*:windows:*:*",
                  "cpe:2.3:a:eset:endpoint_antivirus:-:*:*:*:*:windows:*:*",
                  "cpe:2.3:a:eset:smart_security:-:*:*:*:business:*:*:*",
                  "cpe:2.3:a:eset:security:-:*:*:*:ultimate:*:*:*",
                  "cpe:2.3:a:eset:smart_security:-:*:*:*:premium:*:*:*",
                  "cpe:2.3:a:eset:nod32:-:-:*:*:*:*:*:*",
                  "cpe:2.3:a:eset:internet_security:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "internet_security",
                "vendor": "eset",
                "versions": [
                  {
                    "lessThan": "1610",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-2003",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-21T14:03:09.499428Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-21T14:18:48.023Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T18:56:22.634Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://support.eset.com/ca8674"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Antivirus and antispyware scanner module"
              ],
              "product": "ESET NOD32 Antivirus",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThan": "1610",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Antivirus and antispyware scanner module"
              ],
              "product": "ESET Internet Security",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThan": "1610",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Antivirus and antispyware scanner module"
              ],
              "product": "ESET Smart Security Premium",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThan": "1610",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Antivirus and antispyware scanner module"
              ],
              "product": "ESET Security Ultimate",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThan": "1610",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Antivirus and antispyware scanner module"
              ],
              "product": "ESET Small Business Security",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThan": "1610",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Antivirus and antispyware scanner module"
              ],
              "product": "ESET Safe Server",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThan": "1610",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Antivirus and antispyware scanner module"
              ],
              "product": "ESET Endpoint Antivirus for Windows",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThan": "1610",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Antivirus and antispyware scanner module"
              ],
              "product": "ESET Endpoint Security for Windows",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThan": "1610",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Antivirus and antispyware scanner module"
              ],
              "product": "ESET Server Security for Windows Server",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThan": "1610",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Antivirus and antispyware scanner module"
              ],
              "product": "ESET Mail Security for Microsoft Exchange Server",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThan": "1610",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Antivirus and antispyware scanner module"
              ],
              "product": "ESET Mail Security for IBM Domino",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThan": "1610",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Antivirus and antispyware scanner module"
              ],
              "product": "ESET Security for Microsoft SharePoint Server",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThan": "1610",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Antivirus and antispyware scanner module"
              ],
              "product": "ESET File Security for Microsoft Azure",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThan": "1610",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2024-06-20T10:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Local privilege escalation vulnerability allowed an attacker to misuse ESET\u0027s file operations during a restore operation from quarantine."
                }
              ],
              "value": "Local privilege escalation vulnerability allowed an attacker to misuse ESET\u0027s file operations during a restore operation from quarantine."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-233",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-233 Privilege Escalation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-269",
                  "description": "CWE-269 Improper Privilege Management",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-21T07:20:03.749Z",
            "orgId": "4a9b9929-2450-4021-b7b9-469a0255b215",
            "shortName": "ESET"
          },
          "references": [
            {
              "url": "https://support.eset.com/ca8674"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Local Privilege Escalation in Quarantine of ESET products for Windows",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4a9b9929-2450-4021-b7b9-469a0255b215",
        "assignerShortName": "ESET",
        "cveId": "CVE-2024-2003",
        "datePublished": "2024-06-21T07:20:03.749Z",
        "dateReserved": "2024-02-29T10:37:14.649Z",
        "dateUpdated": "2024-08-01T18:56:22.634Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-0353 (GCVE-0-2024-0353)

    Vulnerability from nvd – Published: 2024-02-15 07:40 – Updated: 2025-12-10 19:33
    VLAI
    Title
    Local privilege escalation in Windows products
    Summary
    Local privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to delete files without having proper permission.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-20 19:22 UTC
    CWE
    • CWE-269 - Improper Privilege Management
    Impacted products
    Vendor Product Version
    ESET, spol. s r.o. ESET NOD32 Antivirus Affected: 0 , ≤ 16.2.15.0 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Internet Security Affected: 0 , ≤ 16.2.15.0 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Smart Security Premium Affected: 0 , ≤ 16.2.15.0 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Security Ultimate Affected: 0 , ≤ 16.2.15.0 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Endpoint Antivirus for Windows Affected: 0 , ≤ 10.1.2058.0 (custom)
    Affected: 0 , ≤ 10.0.2049.0 (custom)
    Affected: 0 , ≤ 9.1.2066.0 (custom)
    Affected: 0 , ≤ 8.1.2052.0 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Endpoint Security for Windows Affected: 0 , ≤ 10.1.2058.0 (custom)
    Affected: 0 , ≤ 10.0.2049.0 (custom)
    Affected: 0 , ≤ 9.1.2066.0 (custom)
    Affected: 0 , ≤ 8.1.2052.0 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Server Security for Windows Server Affected: 0 , ≤ 10.0.12014.0 (custom)
    Affected: 0 , ≤ 9.0.12018.0 (custom)
    Affected: 0 , ≤ 8.0.12015.0 (custom)
    Affected: 0 , ≤ 7.3.12011.0 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Mail Security for Microsoft Exchange Server Affected: 0 , ≤ 10.1.10010.0 (custom)
    Affected: 0 , ≤ 10.0.10017.0 (custom)
    Affected: 0 , ≤ 9.0.10011.0 (custom)
    Affected: 0 , ≤ 8.0.10022.0 (custom)
    Affected: 0 , ≤ 7.3.10014.0 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Mail Security for IBM Domino Affected: 0 , ≤ 10.0.14006.0 (custom)
    Affected: 0 , ≤ 9.0.14007.0 (custom)
    Affected: 0 , ≤ 8.0.14010.0 (custom)
    Affected: 0 , ≤ 7.3.14004.0 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Security for Microsoft SharePoint Server Affected: 0 , ≤ 10.0.15004.0 (custom)
    Affected: 0 , ≤ 9.0.15005.0 (custom)
    Affected: 0 , ≤ 8.0.15011.0 (custom)
    Affected: 0 , ≤ 7.3.15004.0 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET File Security for Microsoft Azure Affected: 0 , ≤ all versions (custom)
    Create a notification for this product.
    eset nod32_antivirus Affected: 0 , ≤ 16.2.15.0 (custom)
        cpe:2.3:a:eset:nod32_antivirus:*:*:*:*:*:*:*:*
    Create a notification for this product.
    eset internet_security Affected: 0 , ≤ 16.2.15.0 (custom)
        cpe:2.3:a:eset:internet_security:*:*:*:*:*:*:*:*
    Create a notification for this product.
    eset smart_security_premium Affected: 0 , ≤ 16.2.15.0 (custom)
        cpe:2.3:a:eset:smart_security_premium:*:*:*:*:*:*:*:*
    Create a notification for this product.
    eset security_ultimate Affected: 0 , ≤ 16.2.15.0 (custom)
        cpe:2.3:a:eset:security_ultimate:*:*:*:*:*:*:*:*
    Create a notification for this product.
    eset endpoint_antivirus Affected: 0 , ≤ 10.1.2058.0 (custom)
        cpe:2.3:a:eset:endpoint_antivirus:-:*:*:*:*:windows:*:*
    Create a notification for this product.
    eset endpoint_security Affected: 0 , ≤ 10.1.2058.0 (custom)
        cpe:2.3:a:eset:endpoint_security:-:*:*:*:*:windows:*:*
    Create a notification for this product.
    eset server_security Affected: 0 , ≤ 10.0.12014.0 (custom)
        cpe:2.3:a:eset:server_security:-:*:*:*:*:windows_server:*:*
    Create a notification for this product.
    eset mail_security Affected: 0 , ≤ 10.1.10010.0 (custom)
        cpe:2.3:a:eset:mail_security:-:*:*:*:*:exchange_server:*:*
    Create a notification for this product.
    eset mail_security Affected: 0 , ≤ 10.0.14006.0 (custom)
        cpe:2.3:a:eset:mail_security:-:*:*:*:*:domino:*:*
    Create a notification for this product.
    eset security Affected: 0 , ≤ 10.0.15004.0 (custom)
        cpe:2.3:a:eset:security:-:*:*:*:*:sharepoint_server:*:*
    Create a notification for this product.
    eset file_security Affected: 0 , ≤ * (custom)
        cpe:2.3:a:eset:file_security:-:*:*:*:*:azure:*:*
    Create a notification for this product.
    Date Public
    2024-02-14 11:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2025-12-10T19:33:58.732Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://packetstormsecurity.com/files/182464/ESET-NOD32-Antivirus-18.0.12.0-Unquoted-Service-Path.html"
              },
              {
                "url": "https://packetstormsecurity.com/files/179495/ESET-NOD32-Antivirus-17.2.7.0-Unquoted-Service-Path.html"
              },
              {
                "url": "https://www.exploit-db.com/exploits/51351"
              },
              {
                "url": "https://www.exploit-db.com/exploits/51964"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://support.eset.com/en/ca8612-eset-customer-advisory-link-following-local-privilege-escalation-vulnerability-in-eset-products-for-windows-fixed"
              }
            ],
            "title": "CVE Program Container",
            "x_generator": {
              "engine": "ADPogram 0.0.1"
            }
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:eset:nod32_antivirus:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "nod32_antivirus",
                "vendor": "eset",
                "versions": [
                  {
                    "lessThanOrEqual": "16.2.15.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:eset:internet_security:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "internet_security",
                "vendor": "eset",
                "versions": [
                  {
                    "lessThanOrEqual": "16.2.15.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:eset:smart_security_premium:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "smart_security_premium",
                "vendor": "eset",
                "versions": [
                  {
                    "lessThanOrEqual": "16.2.15.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:eset:security_ultimate:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "security_ultimate",
                "vendor": "eset",
                "versions": [
                  {
                    "lessThanOrEqual": "16.2.15.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:eset:endpoint_antivirus:-:*:*:*:*:windows:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "endpoint_antivirus",
                "vendor": "eset",
                "versions": [
                  {
                    "lessThanOrEqual": "10.1.2058.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:eset:endpoint_security:-:*:*:*:*:windows:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "endpoint_security",
                "vendor": "eset",
                "versions": [
                  {
                    "lessThanOrEqual": "10.1.2058.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:eset:server_security:-:*:*:*:*:windows_server:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "server_security",
                "vendor": "eset",
                "versions": [
                  {
                    "lessThanOrEqual": "10.0.12014.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:eset:mail_security:-:*:*:*:*:exchange_server:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mail_security",
                "vendor": "eset",
                "versions": [
                  {
                    "lessThanOrEqual": "10.1.10010.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:eset:mail_security:-:*:*:*:*:domino:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mail_security",
                "vendor": "eset",
                "versions": [
                  {
                    "lessThanOrEqual": "10.0.14006.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:eset:security:-:*:*:*:*:sharepoint_server:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "security",
                "vendor": "eset",
                "versions": [
                  {
                    "lessThanOrEqual": "10.0.15004.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:eset:file_security:-:*:*:*:*:azure:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "file_security",
                "vendor": "eset",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-0353",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-20T19:22:48.853538Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-20T19:53:00.534Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ESET NOD32 Antivirus",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "16.2.15.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Internet Security",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "16.2.15.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Smart Security Premium",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "16.2.15.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Security Ultimate",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "16.2.15.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Endpoint Antivirus for Windows",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "10.1.2058.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "10.0.2049.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "9.1.2066.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "8.1.2052.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Endpoint Security for Windows",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "10.1.2058.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "10.0.2049.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "9.1.2066.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "8.1.2052.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Server Security for Windows Server",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "10.0.12014.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "9.0.12018.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "8.0.12015.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "7.3.12011.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Mail Security for Microsoft Exchange Server",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "10.1.10010.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "10.0.10017.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "9.0.10011.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "8.0.10022.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "7.3.10014.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Mail Security for IBM Domino",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "10.0.14006.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "9.0.14007.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "8.0.14010.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "7.3.14004.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Security for Microsoft SharePoint Server",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "10.0.15004.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "9.0.15005.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "8.0.15011.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "7.3.15004.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET File Security for Microsoft Azure",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "all versions",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2024-02-14T11:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Local privilege escalation vulnerability potentially allowed an attacker to misuse ESET\u2019s file operations to delete files without having proper permission."
                }
              ],
              "value": "Local privilege escalation vulnerability potentially allowed an attacker to misuse ESET\u2019s file operations to delete files without having proper permission."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-233",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-233 Privilege Escalation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-269",
                  "description": "CWE-269 Improper Privilege Management",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-02-15T07:40:24.786Z",
            "orgId": "4a9b9929-2450-4021-b7b9-469a0255b215",
            "shortName": "ESET"
          },
          "references": [
            {
              "url": "https://support.eset.com/en/ca8612-eset-customer-advisory-link-following-local-privilege-escalation-vulnerability-in-eset-products-for-windows-fixed"
            }
          ],
          "source": {
            "advisory": "ca8612",
            "discovery": "UNKNOWN"
          },
          "title": "Local privilege escalation in Windows products",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4a9b9929-2450-4021-b7b9-469a0255b215",
        "assignerShortName": "ESET",
        "cveId": "CVE-2024-0353",
        "datePublished": "2024-02-15T07:40:24.786Z",
        "dateReserved": "2024-01-09T14:21:58.755Z",
        "dateUpdated": "2025-12-10T19:33:58.732Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2023-7043 (GCVE-0-2023-7043)

    Vulnerability from nvd – Published: 2024-01-31 12:51 – Updated: 2024-10-17 17:54
    VLAI
    Title
    Unquoted path privilege vulnerability in ESET products for Windows
    Summary
    Unquoted service path in ESET products allows to drop a prepared program to a specific location and run on boot with the NT AUTHORITY\NetworkService permissions.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-01-31 15:52 UTC
    CWE
    • CWE-428 - Unquoted Search Path or Element
    References
    Date Public
    2024-01-26 11:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T08:50:07.939Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://support.eset.com/en/ca8602"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-7043",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-01-31T15:52:23.258496Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-17T17:54:28.120Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ESET Endpoint Security",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "10.1.2063.x",
                  "status": "affected",
                  "version": "10.1.2046.x",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Endpoint Antivirus",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "10.1.2063.x",
                  "status": "affected",
                  "version": "10.1.2046.x",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET NOD32 Antivirus",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "16.2.15.0",
                  "status": "affected",
                  "version": "16.1.14.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Internet Security",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "16.2.15.0",
                  "status": "affected",
                  "version": "16.1.14.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Smart Security Premium",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "16.2.15.0",
                  "status": "affected",
                  "version": "16.1.14.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Mail Security for Microsoft Exchange Server",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "status": "affected",
                  "version": "10.1.10012.0"
                }
              ]
            }
          ],
          "datePublic": "2024-01-26T11:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Unquoted service path in ESET products allows to \n\n\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003edrop a prepared program to a specific location\u003c/span\u003e\u0026nbsp;and\u0026nbsp;\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003erun on boot with \u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003ethe \n\nNT AUTHORITY\\NetworkService\u0026nbsp;permissions.\u003c/span\u003e"
                }
              ],
              "value": "Unquoted service path in ESET products allows to \n\ndrop a prepared program to a specific location\u00a0and\u00a0run on boot with the \n\nNT AUTHORITY\\NetworkService\u00a0permissions."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-233",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-233 Privilege Escalation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "NONE",
                "baseScore": 3.3,
                "baseSeverity": "LOW",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-428",
                  "description": "CWE-428 Unquoted Search Path or Element",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-01-31T12:52:10.301Z",
            "orgId": "4a9b9929-2450-4021-b7b9-469a0255b215",
            "shortName": "ESET"
          },
          "references": [
            {
              "url": "https://support.eset.com/en/ca8602"
            }
          ],
          "source": {
            "advisory": "ca8602",
            "discovery": "UNKNOWN"
          },
          "title": "Unquoted path privilege vulnerability in ESET products for Windows",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4a9b9929-2450-4021-b7b9-469a0255b215",
        "assignerShortName": "ESET",
        "cveId": "CVE-2023-7043",
        "datePublished": "2024-01-31T12:51:38.253Z",
        "dateReserved": "2023-12-21T12:14:56.731Z",
        "dateUpdated": "2024-10-17T17:54:28.120Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-5594 (GCVE-0-2023-5594)

    Vulnerability from nvd – Published: 2023-12-21 11:30 – Updated: 2024-08-02 08:07
    VLAI
    Title
    Improper following of a certificate's chain of trust in ESET security products
    Summary
    Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or SHA1 algorithm as trusted.
    CWE
    • CWE-295 - Improper Certificate Validation
    Date Public
    2023-12-20 11:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T08:07:32.481Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://support.eset.com/en/ca8562-eset-customer-advisory-improper-following-of-a-certificates-chain-of-trust-in-eset-security-products-fixed"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Internet protection module"
              ],
              "product": "ESET NOD32 Antivirus",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1464"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Internet protection module"
              ],
              "product": "ESET Internet Security",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1464"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Internet protection module"
              ],
              "product": "ESET Smart Security Premium",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1464"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Internet protection module"
              ],
              "product": "ESET Security Ultimate",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1464"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Internet protection module"
              ],
              "product": "ESET Endpoint Antivirus",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1464"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Internet protection module"
              ],
              "product": "ESET Endpoint Security",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1464"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Internet protection module"
              ],
              "product": "ESET Endpoint Antivirus for Linux 10.0 and above",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1464"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Internet protection module"
              ],
              "product": "ESET Server Security for Windows Server",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1464"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Internet protection module"
              ],
              "product": "ESET Mail Security for Microsoft Exchange Server",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1464"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Internet protection module"
              ],
              "product": "ESET Mail Security for IBM Domino",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1464"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Internet protection module"
              ],
              "product": "ESET Security for Microsoft SharePoint Server",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1464"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Internet protection module"
              ],
              "product": "ESET File Security for Microsoft Azure",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1464"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Internet protection module"
              ],
              "product": "ESET Server Security for Linux 10.1 and above ",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1464"
                }
              ]
            }
          ],
          "datePublic": "2023-12-20T11:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Improper validation of the server\u2019s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or SHA1 algorithm as trusted."
                }
              ],
              "value": "Improper validation of the server\u2019s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or SHA1 algorithm as trusted."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-94",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-94 Man in the Middle Attack"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-295",
                  "description": "CWE-295 Improper Certificate Validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-12-21T11:30:41.256Z",
            "orgId": "4a9b9929-2450-4021-b7b9-469a0255b215",
            "shortName": "ESET"
          },
          "references": [
            {
              "url": "https://support.eset.com/en/ca8562-eset-customer-advisory-improper-following-of-a-certificates-chain-of-trust-in-eset-security-products-fixed"
            }
          ],
          "source": {
            "advisory": "ca8562",
            "discovery": "UNKNOWN"
          },
          "title": "Improper following of a certificate\u0027s chain of trust\u202fin ESET security products",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4a9b9929-2450-4021-b7b9-469a0255b215",
        "assignerShortName": "ESET",
        "cveId": "CVE-2023-5594",
        "datePublished": "2023-12-21T11:30:41.256Z",
        "dateReserved": "2023-10-16T08:12:50.985Z",
        "dateUpdated": "2024-08-02T08:07:32.481Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2025-13818 (GCVE-0-2025-13818)

    Vulnerability from cvelistv5 – Published: 2026-02-06 13:13 – Updated: 2026-02-06 14:25
    VLAI
    Title
    Local privilege escalation in ESET Management Agent for Windows
    Summary
    Local privilege escalation vulnerability via insecure temporary batch file execution in ESET Management Agent
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-02-06 14:23 UTC
    CWE
    • CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition
    Impacted products
    Vendor Product Version
    ESET spol s.r.o. ESET Management Agent Affected: 0 , ≤ 12.5.2104.0 (custom)
    Create a notification for this product.
    Date Public
    2026-02-06 11:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-13818",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-02-06T14:23:49.218691Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-02-06T14:25:02.493Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "Windows"
              ],
              "product": "ESET Management Agent",
              "vendor": "ESET spol s.r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "12.5.2104.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2026-02-06T11:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Local privilege escalation vulnerability via insecure temporary batch file execution in ESET Management Agent"
                }
              ],
              "value": "Local privilege escalation vulnerability via insecure temporary batch file execution in ESET Management Agent"
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-233",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-233 Privilege Escalation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "LOCAL",
                "baseScore": 8.3,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "HIGH",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-367",
                  "description": "CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-02-06T13:13:47.046Z",
            "orgId": "4a9b9929-2450-4021-b7b9-469a0255b215",
            "shortName": "ESET"
          },
          "references": [
            {
              "url": "https://support.eset.com/en/ca8913-eset-customer-advisory-local-privilege-escalation-via-insecure-temporary-batch-file-execution-in-eset-management-agent-for-windows-fixed"
            }
          ],
          "source": {
            "advisory": "ca8913",
            "discovery": "UNKNOWN"
          },
          "title": "Local privilege escalation in ESET Management Agent for Windows",
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4a9b9929-2450-4021-b7b9-469a0255b215",
        "assignerShortName": "ESET",
        "cveId": "CVE-2025-13818",
        "datePublished": "2026-02-06T13:13:47.046Z",
        "dateReserved": "2025-12-01T07:56:48.667Z",
        "dateUpdated": "2026-02-06T14:25:02.493Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-4952 (GCVE-0-2025-4952)

    Vulnerability from cvelistv5 – Published: 2025-10-31 12:28 – Updated: 2025-10-31 14:18
    VLAI
    Title
    Denial-of-service vulnerability in ESET security products for Windows
    Summary
    Tampering of the registry entries might have led to preventing the ESET security products from starting correctly on the next system startup or to unauthorized changes in the product's configuration.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-10-31 14:18 UTC
    CWE
    • CWE-732 - Incorrect Permission Assignment for Critical Resource
    Date Public
    2025-08-22 10:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-4952",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-10-31T14:18:06.194469Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-10-31T14:18:16.911Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "hips"
              ],
              "platforms": [
                "Windows"
              ],
              "product": "ESET NOD32 Antivirus",
              "vendor": "ESET",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1496",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "HIPS support module"
              ],
              "product": "ESET Internet Security",
              "vendor": "ESET",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1496"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "HIPS support module"
              ],
              "product": "ESET Smart Security Premium",
              "vendor": "ESET",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1496"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "HIPS support module"
              ],
              "product": "ESET Security Ultimate",
              "vendor": "ESET",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1496",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "HIPS support module"
              ],
              "product": "ESET Small Business Security",
              "vendor": "ESET",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1496",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "HIPS support module"
              ],
              "product": "ESET Safe Server",
              "vendor": "ESET",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1496",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "HIPS support module"
              ],
              "product": "ESET Endpoint Antivirus",
              "vendor": "ESET",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1496",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "HIPS support module"
              ],
              "product": "ESET Endpoint Security for Windows",
              "vendor": "ESET",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1496",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "HIPS support module"
              ],
              "product": "ESET Server Security for Windows Server",
              "vendor": "ESET",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1496",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "HIPS support module"
              ],
              "product": "ESET Mail Security for Microsoft Exchange Server",
              "vendor": "ESET",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1496",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "HIPS support module"
              ],
              "product": "ESET Mail Security for IBM Domino",
              "vendor": "ESET",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1496",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "HIPS support module"
              ],
              "product": "ESET Security for Microsoft SharePoint Server",
              "vendor": "ESET",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1496",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "HIPS support module"
              ],
              "product": "ESET File Security for Microsoft Azure",
              "vendor": "ESET",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1496",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:eset:eset_nod32_antivirus:1496:*:windows:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                },
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:eset:eset_internet_security:1496:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                },
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:eset:eset_smart_security_premium:1496:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                },
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:eset:eset_security_ultimate:1496:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                },
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:eset:eset_small_business_security:1496:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                },
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:eset:eset_safe_server:1496:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                },
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:eset:eset_endpoint_antivirus:1496:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                },
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:eset:eset_endpoint_security_for_windows:1496:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                },
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:eset:eset_server_security_for_windows_server:1496:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                },
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:eset:eset_mail_security_for_microsoft_exchange_server:1496:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                },
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:eset:eset_mail_security_for_ibm_domino:1496:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                },
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:eset:eset_security_for_microsoft_sharepoint_server:1496:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                },
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:eset:eset_file_security_for_microsoft_azure:1496:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "datePublic": "2025-08-22T10:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eTampering of the registry entries might have led to preventing the ESET security products from starting correctly on the next system startup or to unauthorized changes in the product\u0027s configuration.\u003c/span\u003e"
                }
              ],
              "value": "Tampering of the registry entries might have led to preventing the ESET security products from starting correctly on the next system startup or to unauthorized changes in the product\u0027s configuration."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-203",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-203 Manipulate Registry Information"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "LOCAL",
                "baseScore": 6.8,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "HIGH",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-732",
                  "description": "CWE-732 Incorrect Permission Assignment for Critical Resource",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-10-31T12:28:15.267Z",
            "orgId": "4a9b9929-2450-4021-b7b9-469a0255b215",
            "shortName": "ESET"
          },
          "references": [
            {
              "url": "https://support.eset.com/en/ca8853-eset-customer-advisory-denial-of-service-vulnerability-in-eset-security-products-for-windows-fixed"
            }
          ],
          "source": {
            "advisory": "ca8853",
            "discovery": "UNKNOWN"
          },
          "title": "Denial-of-service vulnerability in ESET security products for Windows",
          "x_generator": {
            "engine": "Vulnogram 0.4.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4a9b9929-2450-4021-b7b9-469a0255b215",
        "assignerShortName": "ESET",
        "cveId": "CVE-2025-4952",
        "datePublished": "2025-10-31T12:28:15.267Z",
        "dateReserved": "2025-05-19T10:36:38.958Z",
        "dateUpdated": "2025-10-31T14:18:16.911Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-7400 (GCVE-0-2024-7400)

    Vulnerability from cvelistv5 – Published: 2024-09-27 07:02 – Updated: 2024-09-27 18:54
    VLAI
    Title
    Local privilege escalation in ESET products for Windows
    Summary
    The vulnerability potentially allowed an attacker to misuse ESET’s file operations during the removal of a detected file on the Windows operating system to delete files without having proper permissions to do so.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-27 17:57 UTC
    CWE
    • CWE-1386 - Insecure Operation on Windows Junction / Mount Point
    Impacted products
    Vendor Product Version
    ESET, spol. s r.o. ESET NOD32 Antivirus Affected: 0 , ≤ 1250 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Internet Security Affected: 0 , ≤ 1250 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Smart Security Premium Affected: 0 , ≤ 1250 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Security Ultimate Affected: 0 , ≤ 1250 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Small Business Security Affected: 0 , ≤ 1250 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Safe Server Affected: 0 , ≤ 1250 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Endpoint Antivirus Affected: 0 , ≤ 1250 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Endpoint Security for Windows Affected: 0 , ≤ 1250 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Server Security for Windows Server Affected: 0 , ≤ 1250 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Mail Security for Microsoft Exchange Server Affected: 0 , ≤ 1250 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Mail Security for IBM Domino Affected: 0 , ≤ 1250 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Security for Microsoft SharePoint Server Affected: 0 , ≤ 1250 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET File Security for Microsoft Azure Affected: 0 , ≤ 1250 (custom)
    Create a notification for this product.
    eset mail_security Affected: 0 , ≤ 1250 (custom)
        cpe:2.3:a:eset:security:-:*:*:*:*:sharepoint_server:*:*
        cpe:2.3:a:eset:safe_server:-:*:*:*:*:*:*:*
        cpe:2.3:a:eset:security_ultimate:*:*:*:*:*:*:*:*
        cpe:2.3:a:eset:server_security:-:*:*:*:*:windows_server:*:*
        cpe:2.3:a:eset:small_business_security:*:*:*:*:*:*:*:*
        cpe:2.3:a:eset:smart_security:-:*:*:*:premium:*:*:*
        cpe:2.3:a:eset:nod32_antivirus:*:*:*:*:*:*:*:*
        cpe:2.3:a:eset:endpoint_antivirus:*:*:*:*:*:*:*:*
        cpe:2.3:a:eset:endpoint_security:-:*:*:*:*:windows:*:*
        cpe:2.3:a:eset:file_security:-:*:*:*:*:azure:*:*
        cpe:2.3:a:eset:internet_security:*:*:*:*:*:*:*:*
        cpe:2.3:a:eset:mail_security:-:*:*:*:*:domino:*:*
        cpe:2.3:a:eset:mail_security:-:*:*:*:*:exchange_server:*:*
    Create a notification for this product.
    Date Public
    2024-09-20 10:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:eset:security:-:*:*:*:*:sharepoint_server:*:*",
                  "cpe:2.3:a:eset:safe_server:-:*:*:*:*:*:*:*",
                  "cpe:2.3:a:eset:security_ultimate:*:*:*:*:*:*:*:*",
                  "cpe:2.3:a:eset:server_security:-:*:*:*:*:windows_server:*:*",
                  "cpe:2.3:a:eset:small_business_security:*:*:*:*:*:*:*:*",
                  "cpe:2.3:a:eset:smart_security:-:*:*:*:premium:*:*:*",
                  "cpe:2.3:a:eset:nod32_antivirus:*:*:*:*:*:*:*:*",
                  "cpe:2.3:a:eset:endpoint_antivirus:*:*:*:*:*:*:*:*",
                  "cpe:2.3:a:eset:endpoint_security:-:*:*:*:*:windows:*:*",
                  "cpe:2.3:a:eset:file_security:-:*:*:*:*:azure:*:*",
                  "cpe:2.3:a:eset:internet_security:*:*:*:*:*:*:*:*",
                  "cpe:2.3:a:eset:mail_security:-:*:*:*:*:domino:*:*",
                  "cpe:2.3:a:eset:mail_security:-:*:*:*:*:exchange_server:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "mail_security",
                "vendor": "eset",
                "versions": [
                  {
                    "lessThanOrEqual": "1250",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-7400",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-27T17:57:43.358687Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-27T18:54:39.099Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Cleaner module"
              ],
              "product": "ESET NOD32 Antivirus",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "1250",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Cleaner module"
              ],
              "product": "ESET Internet Security",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "1250",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Cleaner module"
              ],
              "product": "ESET Smart Security Premium",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "1250",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Cleaner module"
              ],
              "product": "ESET Security Ultimate",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "1250",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Cleaner module"
              ],
              "product": "ESET Small Business Security",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "1250",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Cleaner module"
              ],
              "product": "ESET Safe Server",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "1250",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Cleaner module"
              ],
              "product": "ESET Endpoint Antivirus",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "1250",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Cleaner module"
              ],
              "product": "ESET Endpoint Security for Windows",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "1250",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Cleaner module"
              ],
              "product": "ESET Server Security for Windows Server",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "1250",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Cleaner module"
              ],
              "product": "ESET Mail Security for Microsoft Exchange Server",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "1250",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Cleaner module"
              ],
              "product": "ESET Mail Security for IBM Domino",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "1250",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Cleaner module"
              ],
              "product": "ESET Security for Microsoft SharePoint Server",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "1250",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Cleaner module"
              ],
              "product": "ESET File Security for Microsoft Azure",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "1250",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2024-09-20T10:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eThe vulnerability potentially allowed an attacker to misuse ESET\u2019s file operations during the removal of a detected file on the Windows operating system to delete files without having proper permissions to do so.\u003c/span\u003e"
                }
              ],
              "value": "The vulnerability potentially allowed an attacker to misuse ESET\u2019s file operations during the removal of a detected file on the Windows operating system to delete files without having proper permissions to do so."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-233",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-233 Privilege Escalation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "LOCAL",
                "baseScore": 8.5,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-1386",
                  "description": "CWE-1386 Insecure Operation on Windows Junction / Mount Point",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-09-27T07:02:28.931Z",
            "orgId": "4a9b9929-2450-4021-b7b9-469a0255b215",
            "shortName": "ESET"
          },
          "references": [
            {
              "url": "https://support.eset.com/en/ca8726-local-privilege-escalation-fixed-for-vulnerability-during-detected-file-removal-in-eset-products-for-windows"
            }
          ],
          "source": {
            "advisory": "ca8726",
            "discovery": "UNKNOWN"
          },
          "title": "Local privilege escalation in ESET products for Windows",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4a9b9929-2450-4021-b7b9-469a0255b215",
        "assignerShortName": "ESET",
        "cveId": "CVE-2024-7400",
        "datePublished": "2024-09-27T07:02:28.931Z",
        "dateReserved": "2024-08-02T07:12:41.358Z",
        "dateUpdated": "2024-09-27T18:54:39.099Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-3779 (GCVE-0-2024-3779)

    Vulnerability from cvelistv5 – Published: 2024-07-16 08:17 – Updated: 2024-08-01 20:20
    VLAI
    Title
    Denial of Service in ESET products for Windows
    Summary
    Denial of service vulnerability present shortly after product installation or upgrade, potentially allowed an attacker to render ESET’s security product inoperable, provided non-default preconditions were met.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-07-16 13:10 UTC
    CWE
    • CWE-276 - Incorrect Default Permissions
    References
    Date Public
    2024-07-12 10:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-3779",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-07-16T13:10:29.360811Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-07-16T13:10:35.421Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T20:20:01.654Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://support.eset.com/en/ca8688"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ESET NOD32 Antivirus",
              "vendor": "ESET s.r.o",
              "versions": [
                {
                  "lessThanOrEqual": "17.1.13.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Internet Security",
              "vendor": "ESET s.r.o",
              "versions": [
                {
                  "lessThanOrEqual": "17.1.13.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Smart Security Premium",
              "vendor": "ESET s.r.o",
              "versions": [
                {
                  "lessThanOrEqual": "17.1.13.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Security Ultimate",
              "vendor": "ESET s.r.o",
              "versions": [
                {
                  "lessThanOrEqual": "17.1.13.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Endpoint Antivirus for Windows",
              "vendor": "ESET s.r.o",
              "versions": [
                {
                  "lessThanOrEqual": "11.0.2044.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Endpoint Security for Windows",
              "vendor": "ESET s.r.o",
              "versions": [
                {
                  "lessThanOrEqual": "11.0.2044.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Server Security for Windows Server",
              "vendor": "ESET s.r.o",
              "versions": [
                {
                  "lessThanOrEqual": "11.0.12011.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Mail Security for Microsoft Exchange Server",
              "vendor": "ESET s.r.o",
              "versions": [
                {
                  "lessThanOrEqual": "11.0.10005.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Mail Security for IBM Domino",
              "vendor": "ESET s.r.o",
              "versions": [
                {
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Security for Microsoft SharePoint Server",
              "vendor": "ESET s.r.o",
              "versions": [
                {
                  "lessThanOrEqual": "11.0.15002.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2024-07-12T10:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Denial of service vulnerability present shortly after product installation or upgrade, potentially allowed an attacker to render ESET\u2019s security product inoperable, provided non-default preconditions were met."
                }
              ],
              "value": "Denial of service vulnerability present shortly after product installation or upgrade, potentially allowed an attacker to render ESET\u2019s security product inoperable, provided non-default preconditions were met."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-578",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-578 Disable Security Software"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 6.1,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-276",
                  "description": "CWE-276 Incorrect Default Permissions",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-07-16T08:17:59.962Z",
            "orgId": "4a9b9929-2450-4021-b7b9-469a0255b215",
            "shortName": "ESET"
          },
          "references": [
            {
              "url": "https://support.eset.com/en/ca8688"
            }
          ],
          "source": {
            "advisory": "ca8688",
            "discovery": "UNKNOWN"
          },
          "title": "Denial of Service in ESET products for Windows",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4a9b9929-2450-4021-b7b9-469a0255b215",
        "assignerShortName": "ESET",
        "cveId": "CVE-2024-3779",
        "datePublished": "2024-07-16T08:17:59.962Z",
        "dateReserved": "2024-04-15T07:03:57.841Z",
        "dateUpdated": "2024-08-01T20:20:01.654Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-2003 (GCVE-0-2024-2003)

    Vulnerability from cvelistv5 – Published: 2024-06-21 07:20 – Updated: 2024-08-01 18:56
    VLAI
    Title
    Local Privilege Escalation in Quarantine of ESET products for Windows
    Summary
    Local privilege escalation vulnerability allowed an attacker to misuse ESET's file operations during a restore operation from quarantine.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-21 14:03 UTC
    CWE
    • CWE-269 - Improper Privilege Management
    References
    Impacted products
    Vendor Product Version
    ESET, spol. s r.o. ESET NOD32 Antivirus Affected: 0 , < 1610 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Internet Security Affected: 0 , < 1610 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Smart Security Premium Affected: 0 , < 1610 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Security Ultimate Affected: 0 , < 1610 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Small Business Security Affected: 0 , < 1610 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Safe Server Affected: 0 , < 1610 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Endpoint Antivirus for Windows Affected: 0 , < 1610 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Endpoint Security for Windows Affected: 0 , < 1610 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Server Security for Windows Server Affected: 0 , < 1610 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Mail Security for Microsoft Exchange Server Affected: 0 , < 1610 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Mail Security for IBM Domino Affected: 0 , < 1610 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Security for Microsoft SharePoint Server Affected: 0 , < 1610 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET File Security for Microsoft Azure Affected: 0 , < 1610 (custom)
    Create a notification for this product.
    eset internet_security Affected: 0 , < 1610 (custom)
        cpe:2.3:a:eset:safe_server:-:*:*:*:*:*:*:*
        cpe:2.3:a:eset:file_security:-:*:*:*:*:azure:*:*
        cpe:2.3:a:eset:security:-:*:*:*:*:sharepoint_server:*:*
        cpe:2.3:a:eset:mail_security:-:*:*:*:*:domino:*:*
        cpe:2.3:a:eset:server_security:-:*:*:*:*:windows_server:*:*
        cpe:2.3:a:eset:endpoint_security:-:*:*:*:*:windows:*:*
        cpe:2.3:a:eset:endpoint_antivirus:-:*:*:*:*:windows:*:*
        cpe:2.3:a:eset:smart_security:-:*:*:*:business:*:*:*
        cpe:2.3:a:eset:security:-:*:*:*:ultimate:*:*:*
        cpe:2.3:a:eset:smart_security:-:*:*:*:premium:*:*:*
        cpe:2.3:a:eset:nod32:-:-:*:*:*:*:*:*
        cpe:2.3:a:eset:internet_security:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-06-20 10:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:eset:safe_server:-:*:*:*:*:*:*:*",
                  "cpe:2.3:a:eset:file_security:-:*:*:*:*:azure:*:*",
                  "cpe:2.3:a:eset:security:-:*:*:*:*:sharepoint_server:*:*",
                  "cpe:2.3:a:eset:mail_security:-:*:*:*:*:domino:*:*",
                  "cpe:2.3:a:eset:server_security:-:*:*:*:*:windows_server:*:*",
                  "cpe:2.3:a:eset:endpoint_security:-:*:*:*:*:windows:*:*",
                  "cpe:2.3:a:eset:endpoint_antivirus:-:*:*:*:*:windows:*:*",
                  "cpe:2.3:a:eset:smart_security:-:*:*:*:business:*:*:*",
                  "cpe:2.3:a:eset:security:-:*:*:*:ultimate:*:*:*",
                  "cpe:2.3:a:eset:smart_security:-:*:*:*:premium:*:*:*",
                  "cpe:2.3:a:eset:nod32:-:-:*:*:*:*:*:*",
                  "cpe:2.3:a:eset:internet_security:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "internet_security",
                "vendor": "eset",
                "versions": [
                  {
                    "lessThan": "1610",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-2003",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-21T14:03:09.499428Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-21T14:18:48.023Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T18:56:22.634Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://support.eset.com/ca8674"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Antivirus and antispyware scanner module"
              ],
              "product": "ESET NOD32 Antivirus",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThan": "1610",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Antivirus and antispyware scanner module"
              ],
              "product": "ESET Internet Security",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThan": "1610",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Antivirus and antispyware scanner module"
              ],
              "product": "ESET Smart Security Premium",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThan": "1610",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Antivirus and antispyware scanner module"
              ],
              "product": "ESET Security Ultimate",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThan": "1610",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Antivirus and antispyware scanner module"
              ],
              "product": "ESET Small Business Security",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThan": "1610",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Antivirus and antispyware scanner module"
              ],
              "product": "ESET Safe Server",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThan": "1610",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Antivirus and antispyware scanner module"
              ],
              "product": "ESET Endpoint Antivirus for Windows",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThan": "1610",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Antivirus and antispyware scanner module"
              ],
              "product": "ESET Endpoint Security for Windows",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThan": "1610",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Antivirus and antispyware scanner module"
              ],
              "product": "ESET Server Security for Windows Server",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThan": "1610",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Antivirus and antispyware scanner module"
              ],
              "product": "ESET Mail Security for Microsoft Exchange Server",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThan": "1610",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Antivirus and antispyware scanner module"
              ],
              "product": "ESET Mail Security for IBM Domino",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThan": "1610",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Antivirus and antispyware scanner module"
              ],
              "product": "ESET Security for Microsoft SharePoint Server",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThan": "1610",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Antivirus and antispyware scanner module"
              ],
              "product": "ESET File Security for Microsoft Azure",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThan": "1610",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2024-06-20T10:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Local privilege escalation vulnerability allowed an attacker to misuse ESET\u0027s file operations during a restore operation from quarantine."
                }
              ],
              "value": "Local privilege escalation vulnerability allowed an attacker to misuse ESET\u0027s file operations during a restore operation from quarantine."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-233",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-233 Privilege Escalation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-269",
                  "description": "CWE-269 Improper Privilege Management",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-21T07:20:03.749Z",
            "orgId": "4a9b9929-2450-4021-b7b9-469a0255b215",
            "shortName": "ESET"
          },
          "references": [
            {
              "url": "https://support.eset.com/ca8674"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Local Privilege Escalation in Quarantine of ESET products for Windows",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4a9b9929-2450-4021-b7b9-469a0255b215",
        "assignerShortName": "ESET",
        "cveId": "CVE-2024-2003",
        "datePublished": "2024-06-21T07:20:03.749Z",
        "dateReserved": "2024-02-29T10:37:14.649Z",
        "dateUpdated": "2024-08-01T18:56:22.634Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-0353 (GCVE-0-2024-0353)

    Vulnerability from cvelistv5 – Published: 2024-02-15 07:40 – Updated: 2025-12-10 19:33
    VLAI
    Title
    Local privilege escalation in Windows products
    Summary
    Local privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to delete files without having proper permission.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-20 19:22 UTC
    CWE
    • CWE-269 - Improper Privilege Management
    Impacted products
    Vendor Product Version
    ESET, spol. s r.o. ESET NOD32 Antivirus Affected: 0 , ≤ 16.2.15.0 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Internet Security Affected: 0 , ≤ 16.2.15.0 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Smart Security Premium Affected: 0 , ≤ 16.2.15.0 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Security Ultimate Affected: 0 , ≤ 16.2.15.0 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Endpoint Antivirus for Windows Affected: 0 , ≤ 10.1.2058.0 (custom)
    Affected: 0 , ≤ 10.0.2049.0 (custom)
    Affected: 0 , ≤ 9.1.2066.0 (custom)
    Affected: 0 , ≤ 8.1.2052.0 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Endpoint Security for Windows Affected: 0 , ≤ 10.1.2058.0 (custom)
    Affected: 0 , ≤ 10.0.2049.0 (custom)
    Affected: 0 , ≤ 9.1.2066.0 (custom)
    Affected: 0 , ≤ 8.1.2052.0 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Server Security for Windows Server Affected: 0 , ≤ 10.0.12014.0 (custom)
    Affected: 0 , ≤ 9.0.12018.0 (custom)
    Affected: 0 , ≤ 8.0.12015.0 (custom)
    Affected: 0 , ≤ 7.3.12011.0 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Mail Security for Microsoft Exchange Server Affected: 0 , ≤ 10.1.10010.0 (custom)
    Affected: 0 , ≤ 10.0.10017.0 (custom)
    Affected: 0 , ≤ 9.0.10011.0 (custom)
    Affected: 0 , ≤ 8.0.10022.0 (custom)
    Affected: 0 , ≤ 7.3.10014.0 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Mail Security for IBM Domino Affected: 0 , ≤ 10.0.14006.0 (custom)
    Affected: 0 , ≤ 9.0.14007.0 (custom)
    Affected: 0 , ≤ 8.0.14010.0 (custom)
    Affected: 0 , ≤ 7.3.14004.0 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET Security for Microsoft SharePoint Server Affected: 0 , ≤ 10.0.15004.0 (custom)
    Affected: 0 , ≤ 9.0.15005.0 (custom)
    Affected: 0 , ≤ 8.0.15011.0 (custom)
    Affected: 0 , ≤ 7.3.15004.0 (custom)
    Create a notification for this product.
    ESET, spol. s r.o. ESET File Security for Microsoft Azure Affected: 0 , ≤ all versions (custom)
    Create a notification for this product.
    eset nod32_antivirus Affected: 0 , ≤ 16.2.15.0 (custom)
        cpe:2.3:a:eset:nod32_antivirus:*:*:*:*:*:*:*:*
    Create a notification for this product.
    eset internet_security Affected: 0 , ≤ 16.2.15.0 (custom)
        cpe:2.3:a:eset:internet_security:*:*:*:*:*:*:*:*
    Create a notification for this product.
    eset smart_security_premium Affected: 0 , ≤ 16.2.15.0 (custom)
        cpe:2.3:a:eset:smart_security_premium:*:*:*:*:*:*:*:*
    Create a notification for this product.
    eset security_ultimate Affected: 0 , ≤ 16.2.15.0 (custom)
        cpe:2.3:a:eset:security_ultimate:*:*:*:*:*:*:*:*
    Create a notification for this product.
    eset endpoint_antivirus Affected: 0 , ≤ 10.1.2058.0 (custom)
        cpe:2.3:a:eset:endpoint_antivirus:-:*:*:*:*:windows:*:*
    Create a notification for this product.
    eset endpoint_security Affected: 0 , ≤ 10.1.2058.0 (custom)
        cpe:2.3:a:eset:endpoint_security:-:*:*:*:*:windows:*:*
    Create a notification for this product.
    eset server_security Affected: 0 , ≤ 10.0.12014.0 (custom)
        cpe:2.3:a:eset:server_security:-:*:*:*:*:windows_server:*:*
    Create a notification for this product.
    eset mail_security Affected: 0 , ≤ 10.1.10010.0 (custom)
        cpe:2.3:a:eset:mail_security:-:*:*:*:*:exchange_server:*:*
    Create a notification for this product.
    eset mail_security Affected: 0 , ≤ 10.0.14006.0 (custom)
        cpe:2.3:a:eset:mail_security:-:*:*:*:*:domino:*:*
    Create a notification for this product.
    eset security Affected: 0 , ≤ 10.0.15004.0 (custom)
        cpe:2.3:a:eset:security:-:*:*:*:*:sharepoint_server:*:*
    Create a notification for this product.
    eset file_security Affected: 0 , ≤ * (custom)
        cpe:2.3:a:eset:file_security:-:*:*:*:*:azure:*:*
    Create a notification for this product.
    Date Public
    2024-02-14 11:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2025-12-10T19:33:58.732Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://packetstormsecurity.com/files/182464/ESET-NOD32-Antivirus-18.0.12.0-Unquoted-Service-Path.html"
              },
              {
                "url": "https://packetstormsecurity.com/files/179495/ESET-NOD32-Antivirus-17.2.7.0-Unquoted-Service-Path.html"
              },
              {
                "url": "https://www.exploit-db.com/exploits/51351"
              },
              {
                "url": "https://www.exploit-db.com/exploits/51964"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://support.eset.com/en/ca8612-eset-customer-advisory-link-following-local-privilege-escalation-vulnerability-in-eset-products-for-windows-fixed"
              }
            ],
            "title": "CVE Program Container",
            "x_generator": {
              "engine": "ADPogram 0.0.1"
            }
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:eset:nod32_antivirus:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "nod32_antivirus",
                "vendor": "eset",
                "versions": [
                  {
                    "lessThanOrEqual": "16.2.15.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:eset:internet_security:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "internet_security",
                "vendor": "eset",
                "versions": [
                  {
                    "lessThanOrEqual": "16.2.15.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:eset:smart_security_premium:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "smart_security_premium",
                "vendor": "eset",
                "versions": [
                  {
                    "lessThanOrEqual": "16.2.15.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:eset:security_ultimate:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "security_ultimate",
                "vendor": "eset",
                "versions": [
                  {
                    "lessThanOrEqual": "16.2.15.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:eset:endpoint_antivirus:-:*:*:*:*:windows:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "endpoint_antivirus",
                "vendor": "eset",
                "versions": [
                  {
                    "lessThanOrEqual": "10.1.2058.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:eset:endpoint_security:-:*:*:*:*:windows:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "endpoint_security",
                "vendor": "eset",
                "versions": [
                  {
                    "lessThanOrEqual": "10.1.2058.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:eset:server_security:-:*:*:*:*:windows_server:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "server_security",
                "vendor": "eset",
                "versions": [
                  {
                    "lessThanOrEqual": "10.0.12014.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:eset:mail_security:-:*:*:*:*:exchange_server:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mail_security",
                "vendor": "eset",
                "versions": [
                  {
                    "lessThanOrEqual": "10.1.10010.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:eset:mail_security:-:*:*:*:*:domino:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mail_security",
                "vendor": "eset",
                "versions": [
                  {
                    "lessThanOrEqual": "10.0.14006.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:eset:security:-:*:*:*:*:sharepoint_server:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "security",
                "vendor": "eset",
                "versions": [
                  {
                    "lessThanOrEqual": "10.0.15004.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:eset:file_security:-:*:*:*:*:azure:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "file_security",
                "vendor": "eset",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-0353",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-20T19:22:48.853538Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-20T19:53:00.534Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ESET NOD32 Antivirus",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "16.2.15.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Internet Security",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "16.2.15.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Smart Security Premium",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "16.2.15.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Security Ultimate",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "16.2.15.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Endpoint Antivirus for Windows",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "10.1.2058.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "10.0.2049.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "9.1.2066.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "8.1.2052.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Endpoint Security for Windows",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "10.1.2058.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "10.0.2049.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "9.1.2066.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "8.1.2052.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Server Security for Windows Server",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "10.0.12014.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "9.0.12018.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "8.0.12015.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "7.3.12011.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Mail Security for Microsoft Exchange Server",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "10.1.10010.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "10.0.10017.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "9.0.10011.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "8.0.10022.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "7.3.10014.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Mail Security for IBM Domino",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "10.0.14006.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "9.0.14007.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "8.0.14010.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "7.3.14004.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Security for Microsoft SharePoint Server",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "10.0.15004.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "9.0.15005.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "8.0.15011.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "7.3.15004.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET File Security for Microsoft Azure",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "all versions",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2024-02-14T11:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Local privilege escalation vulnerability potentially allowed an attacker to misuse ESET\u2019s file operations to delete files without having proper permission."
                }
              ],
              "value": "Local privilege escalation vulnerability potentially allowed an attacker to misuse ESET\u2019s file operations to delete files without having proper permission."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-233",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-233 Privilege Escalation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-269",
                  "description": "CWE-269 Improper Privilege Management",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-02-15T07:40:24.786Z",
            "orgId": "4a9b9929-2450-4021-b7b9-469a0255b215",
            "shortName": "ESET"
          },
          "references": [
            {
              "url": "https://support.eset.com/en/ca8612-eset-customer-advisory-link-following-local-privilege-escalation-vulnerability-in-eset-products-for-windows-fixed"
            }
          ],
          "source": {
            "advisory": "ca8612",
            "discovery": "UNKNOWN"
          },
          "title": "Local privilege escalation in Windows products",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4a9b9929-2450-4021-b7b9-469a0255b215",
        "assignerShortName": "ESET",
        "cveId": "CVE-2024-0353",
        "datePublished": "2024-02-15T07:40:24.786Z",
        "dateReserved": "2024-01-09T14:21:58.755Z",
        "dateUpdated": "2025-12-10T19:33:58.732Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2023-7043 (GCVE-0-2023-7043)

    Vulnerability from cvelistv5 – Published: 2024-01-31 12:51 – Updated: 2024-10-17 17:54
    VLAI
    Title
    Unquoted path privilege vulnerability in ESET products for Windows
    Summary
    Unquoted service path in ESET products allows to drop a prepared program to a specific location and run on boot with the NT AUTHORITY\NetworkService permissions.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-01-31 15:52 UTC
    CWE
    • CWE-428 - Unquoted Search Path or Element
    References
    Date Public
    2024-01-26 11:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T08:50:07.939Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://support.eset.com/en/ca8602"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-7043",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-01-31T15:52:23.258496Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-17T17:54:28.120Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ESET Endpoint Security",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "10.1.2063.x",
                  "status": "affected",
                  "version": "10.1.2046.x",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Endpoint Antivirus",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "10.1.2063.x",
                  "status": "affected",
                  "version": "10.1.2046.x",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET NOD32 Antivirus",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "16.2.15.0",
                  "status": "affected",
                  "version": "16.1.14.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Internet Security",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "16.2.15.0",
                  "status": "affected",
                  "version": "16.1.14.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Smart Security Premium",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "lessThanOrEqual": "16.2.15.0",
                  "status": "affected",
                  "version": "16.1.14.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ESET Mail Security for Microsoft Exchange Server",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "status": "affected",
                  "version": "10.1.10012.0"
                }
              ]
            }
          ],
          "datePublic": "2024-01-26T11:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Unquoted service path in ESET products allows to \n\n\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003edrop a prepared program to a specific location\u003c/span\u003e\u0026nbsp;and\u0026nbsp;\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003erun on boot with \u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003ethe \n\nNT AUTHORITY\\NetworkService\u0026nbsp;permissions.\u003c/span\u003e"
                }
              ],
              "value": "Unquoted service path in ESET products allows to \n\ndrop a prepared program to a specific location\u00a0and\u00a0run on boot with the \n\nNT AUTHORITY\\NetworkService\u00a0permissions."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-233",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-233 Privilege Escalation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "NONE",
                "baseScore": 3.3,
                "baseSeverity": "LOW",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-428",
                  "description": "CWE-428 Unquoted Search Path or Element",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-01-31T12:52:10.301Z",
            "orgId": "4a9b9929-2450-4021-b7b9-469a0255b215",
            "shortName": "ESET"
          },
          "references": [
            {
              "url": "https://support.eset.com/en/ca8602"
            }
          ],
          "source": {
            "advisory": "ca8602",
            "discovery": "UNKNOWN"
          },
          "title": "Unquoted path privilege vulnerability in ESET products for Windows",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4a9b9929-2450-4021-b7b9-469a0255b215",
        "assignerShortName": "ESET",
        "cveId": "CVE-2023-7043",
        "datePublished": "2024-01-31T12:51:38.253Z",
        "dateReserved": "2023-12-21T12:14:56.731Z",
        "dateUpdated": "2024-10-17T17:54:28.120Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-5594 (GCVE-0-2023-5594)

    Vulnerability from cvelistv5 – Published: 2023-12-21 11:30 – Updated: 2024-08-02 08:07
    VLAI
    Title
    Improper following of a certificate's chain of trust in ESET security products
    Summary
    Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or SHA1 algorithm as trusted.
    CWE
    • CWE-295 - Improper Certificate Validation
    Date Public
    2023-12-20 11:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T08:07:32.481Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://support.eset.com/en/ca8562-eset-customer-advisory-improper-following-of-a-certificates-chain-of-trust-in-eset-security-products-fixed"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Internet protection module"
              ],
              "product": "ESET NOD32 Antivirus",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1464"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Internet protection module"
              ],
              "product": "ESET Internet Security",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1464"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Internet protection module"
              ],
              "product": "ESET Smart Security Premium",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1464"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Internet protection module"
              ],
              "product": "ESET Security Ultimate",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1464"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Internet protection module"
              ],
              "product": "ESET Endpoint Antivirus",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1464"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Internet protection module"
              ],
              "product": "ESET Endpoint Security",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1464"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Internet protection module"
              ],
              "product": "ESET Endpoint Antivirus for Linux 10.0 and above",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1464"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Internet protection module"
              ],
              "product": "ESET Server Security for Windows Server",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1464"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Internet protection module"
              ],
              "product": "ESET Mail Security for Microsoft Exchange Server",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1464"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Internet protection module"
              ],
              "product": "ESET Mail Security for IBM Domino",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1464"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Internet protection module"
              ],
              "product": "ESET Security for Microsoft SharePoint Server",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1464"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Internet protection module"
              ],
              "product": "ESET File Security for Microsoft Azure",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1464"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Internet protection module"
              ],
              "product": "ESET Server Security for Linux 10.1 and above ",
              "vendor": "ESET, spol. s r.o.",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "1464"
                }
              ]
            }
          ],
          "datePublic": "2023-12-20T11:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Improper validation of the server\u2019s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or SHA1 algorithm as trusted."
                }
              ],
              "value": "Improper validation of the server\u2019s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or SHA1 algorithm as trusted."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-94",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-94 Man in the Middle Attack"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-295",
                  "description": "CWE-295 Improper Certificate Validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-12-21T11:30:41.256Z",
            "orgId": "4a9b9929-2450-4021-b7b9-469a0255b215",
            "shortName": "ESET"
          },
          "references": [
            {
              "url": "https://support.eset.com/en/ca8562-eset-customer-advisory-improper-following-of-a-certificates-chain-of-trust-in-eset-security-products-fixed"
            }
          ],
          "source": {
            "advisory": "ca8562",
            "discovery": "UNKNOWN"
          },
          "title": "Improper following of a certificate\u0027s chain of trust\u202fin ESET security products",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4a9b9929-2450-4021-b7b9-469a0255b215",
        "assignerShortName": "ESET",
        "cveId": "CVE-2023-5594",
        "datePublished": "2023-12-21T11:30:41.256Z",
        "dateReserved": "2023-10-16T08:12:50.985Z",
        "dateUpdated": "2024-08-02T08:07:32.481Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }