7.1

CVE-2022-27167

Arbitrary File Deletion in ESET products for Windows

Privilege escalation vulnerability in Windows products of ESET, spol. s r.o. allows attacker to exploit "Repair" and "Uninstall" features what may lead to arbitrary file deletion. This issue affects: ESET, spol. s r.o. ESET NOD32 Antivirus 11.2 versions prior to 15.1.12.0. ESET, spol. s r.o. ESET Internet Security 11.2 versions prior to 15.1.12.0. ESET, spol. s r.o. ESET Smart Security Premium 11.2 versions prior to 15.1.12.0. ESET, spol. s r.o. ESET Endpoint Antivirus 6.0 versions prior to 9.0.2046.0. ESET, spol. s r.o. ESET Endpoint Security 6.0 versions prior to 9.0.2046.0. ESET, spol. s r.o. ESET Server Security for Microsoft Windows Server 8.0 versions prior to 9.0.12012.0. ESET, spol. s r.o. ESET File Security for Microsoft Windows Server 8.0.12013.0. ESET, spol. s r.o. ESET Mail Security for Microsoft Exchange Server 6.0 versions prior to 8.0.10020.0. ESET, spol. s r.o. ESET Mail Security for IBM Domino 6.0 versions prior to 8.0.14011.0. ESET, spol. s r.o. ESET Security for Microsoft SharePoint Server 6.0 versions prior to 8.0.15009.0.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Eset ≫ Endpoint Antivirus SwPlatform windows Version >= 6.0 < 8.0.2053.0
Eset ≫ Endpoint Antivirus SwPlatform windows Version >= 8.1 < 8.1.2050.0
Eset ≫ Endpoint Antivirus SwPlatform windows Version >= 9.0 < 9.0.2046.0
Eset ≫ Endpoint Security SwPlatform windows Version >= 6.0 < 8.0.2053.0
Eset ≫ Endpoint Security SwPlatform windows Version >= 8.1 < 8.1.2050.0
Eset ≫ Endpoint Security SwPlatform windows Version >= 9.0 < 9.0.2046.0
Eset ≫ File Security SwPlatform windows_server Version >= 6.0 < 8.0.12013.0
Eset ≫ Internet Security SwPlatform windows Version >= 11.2 < 15.1.12.0
Eset ≫ Mail Security SwPlatform exchange_server Version >= 6.0 < 8.0.10020.0
Eset ≫ Mail Security SwPlatform domino Version >= 6.0 < 8.0.14011.0
Eset ≫ Nod32 Antivirus SwPlatform windows Version >= 11.2 < 15.1.12.0
Eset ≫ Security SwPlatform sharepoint_server Version >= 6.0 < 8.0.15009.0
Eset ≫ Server Security SwPlatform azure Version >= 6.0
Eset ≫ Server Security SwPlatform windows_server Version >= 8.0 < 9.0.12012.0
Eset ≫ Smart Security SwEdition premium SwPlatform windows Version >= 11.2 < 15.1.12.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.079
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
NIST 3.6 3.9 4.9
AV:L/AC:L/Au:N/C:N/I:P/A:P
security@eset.com 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CWE-280 Improper Handling of Insufficient Permissions or Privileges

The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.

CWE-755 Improper Handling of Exceptional Conditions

The product does not handle or incorrectly handles an exceptional condition.