7.8

CVE-2024-0353

Local privilege escalation in Windows products

Local privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to delete files without having proper permission.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Eset ≫ Endpoint Antivirus SwPlatform windows Version < 8.1.2062.0
Eset ≫ Endpoint Antivirus SwPlatform windows Version >= 9.0 < 9.1.2071.0
Eset ≫ Endpoint Antivirus SwPlatform windows Version >= 10.0 < 10.0.2052.0
Eset ≫ Endpoint Antivirus SwPlatform windows Version >= 10.1 < 10.1.2063.0
Eset ≫ Endpoint Antivirus SwPlatform windows Version >= 11.0 < 11.0.2032.0
Eset ≫ Endpoint Security SwPlatform windows Version < 8.1.2062.0
Eset ≫ Endpoint Security SwPlatform windows Version >= 9.0 < 9.1.2071.0
Eset ≫ Endpoint Security SwPlatform windows Version >= 10.0 < 10.0.2052.0
Eset ≫ Endpoint Security SwPlatform windows Version >= 10.1 < 10.1.2063.0
Eset ≫ Endpoint Security SwPlatform windows Version >= 11.0 < 11.0.2032.0
Eset ≫ File Security SwPlatform azure
Eset ≫ Internet Security Version < 17.0.10.0
Eset ≫ Mail Security SwPlatform exchange_server Version < 7.3.10018.0
Eset ≫ Mail Security SwPlatform domino Version < 7.3.14006.0
Eset ≫ Mail Security SwPlatform exchange_server Version >= 8.0 < 8.0.10024.0
Eset ≫ Mail Security SwPlatform domino Version >= 8.0 < 8.0.14014.0
Eset ≫ Mail Security SwPlatform exchange_server Version >= 9.0 < 9.0.10012.0
Eset ≫ Mail Security SwPlatform domino Version >= 9.0 < 9.0.14008.0
Eset ≫ Mail Security SwPlatform exchange_server Version >= 10.0 < 10.0.10018.0
Eset ≫ Mail Security SwPlatform domino Version >= 10.0 < 10.0.14007.0
Eset ≫ Mail Security SwPlatform exchange_server Version >= 10.1 < 10.1.10014.0
Eset ≫ Nod32 Antivirus Version < 17.0.10.0
Eset ≫ Security SwPlatform sharepoint_server Version < 7.3.15006.0
Eset ≫ Security SwEdition ultimate Version < 17.0.10.0
Eset ≫ Security SwPlatform sharepoint_server Version >= 8.0 < 8.0.15012.0
Eset ≫ Security SwPlatform sharepoint_server Version >= 9.0 < 9.0.15006.0
Eset ≫ Security SwPlatform sharepoint_server Version >= 10.0 < 10.0.15005.0
Eset ≫ Server Security SwPlatform windows_server Version < 7.3.12013.0
Eset ≫ Server Security SwPlatform windows_server Version >= 8.0 < 8.0.12016.0
Eset ≫ Server Security SwPlatform windows_server Version >= 9.0 < 9.0.12019.0
Eset ≫ Server Security SwPlatform windows_server Version >= 10.0 < 10.0.12015.0
Eset ≫ Smart Security SwEdition premium Version < 17.0.10.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.55% 0.417
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
security@eset.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

https://support.eset.com/en/ca8612-eset-customer-advisory-link-following-local-privilege-escalation-vulnerability-in-eset-products-for-windows-fixed
Vendor Advisory
https://packetstormsecurity.com/files/179495/ESET-NOD32-Antivirus-17.2.7.0-Unquoted-Service-Path.html
Broken Link
https://packetstormsecurity.com/files/182464/ESET-NOD32-Antivirus-18.0.12.0-Unquoted-Service-Path.html
Broken Link
https://www.exploit-db.com/exploits/51351
https://www.exploit-db.com/exploits/51964