7.8

CVE-2024-0353

Local privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to delete files without having proper permission.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
EsetEndpoint Antivirus SwPlatformwindows Version < 8.1.2062.0
EsetEndpoint Antivirus SwPlatformwindows Version >= 9.0 < 9.1.2071.0
EsetEndpoint Antivirus SwPlatformwindows Version >= 10.0 < 10.0.2052.0
EsetEndpoint Antivirus SwPlatformwindows Version >= 10.1 < 10.1.2063.0
EsetEndpoint Antivirus SwPlatformwindows Version >= 11.0 < 11.0.2032.0
EsetEndpoint Security SwPlatformwindows Version < 8.1.2062.0
EsetEndpoint Security SwPlatformwindows Version >= 9.0 < 9.1.2071.0
EsetEndpoint Security SwPlatformwindows Version >= 10.0 < 10.0.2052.0
EsetEndpoint Security SwPlatformwindows Version >= 10.1 < 10.1.2063.0
EsetEndpoint Security SwPlatformwindows Version >= 11.0 < 11.0.2032.0
EsetFile Security SwPlatformazure
EsetInternet Security Version < 17.0.10.0
EsetMail Security SwPlatformexchange_server Version < 7.3.10018.0
EsetMail Security SwPlatformdomino Version < 7.3.14006.0
EsetMail Security SwPlatformexchange_server Version >= 8.0 < 8.0.10024.0
EsetMail Security SwPlatformdomino Version >= 8.0 < 8.0.14014.0
EsetMail Security SwPlatformexchange_server Version >= 9.0 < 9.0.10012.0
EsetMail Security SwPlatformdomino Version >= 9.0 < 9.0.14008.0
EsetMail Security SwPlatformexchange_server Version >= 10.0 < 10.0.10018.0
EsetMail Security SwPlatformdomino Version >= 10.0 < 10.0.14007.0
EsetMail Security SwPlatformexchange_server Version >= 10.1 < 10.1.10014.0
EsetNod32 Antivirus Version < 17.0.10.0
EsetSecurity SwPlatformsharepoint_server Version < 7.3.15006.0
EsetSecurity SwEditionultimate Version < 17.0.10.0
EsetSecurity SwPlatformsharepoint_server Version >= 8.0 < 8.0.15012.0
EsetSecurity SwPlatformsharepoint_server Version >= 9.0 < 9.0.15006.0
EsetSecurity SwPlatformsharepoint_server Version >= 10.0 < 10.0.15005.0
EsetServer Security SwPlatformwindows_server Version < 7.3.12013.0
EsetServer Security SwPlatformwindows_server Version >= 8.0 < 8.0.12016.0
EsetServer Security SwPlatformwindows_server Version >= 9.0 < 9.0.12019.0
EsetServer Security SwPlatformwindows_server Version >= 10.0 < 10.0.12015.0
EsetSmart Security SwEditionpremium Version < 17.0.10.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.1% 0.287
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
security@eset.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.