7.8
CVE-2023-3160
- EPSS 0.18%
- Veröffentlicht 14.08.2023 10:15:09
- Zuletzt bearbeitet 21.11.2024 08:16:35
- Erkennungen
Local privilege escalation in security products for Windows
The vulnerability potentially allows an attacker to misuse ESET’s file operations during the module update to delete or move files without having proper permissions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Eset ≫ Endpoint Antivirus Version - SwPlatform -
Eset ≫ Endpoint Security Version -
Eset ≫ Internet Security Version -
Eset ≫ Mail Security Version - SwPlatform domino
Eset ≫ Mail Security Version - SwPlatform exchange_server
Eset ≫ Server Security Version - SwPlatform windows_server
Eset ≫ Smart Security Version - SwEdition premium
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.18% | 0.073 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| security@eset.com | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
https://support.eset.com/en/ca8466