6.1

CVE-2024-3779

Denial of service vulnerability present shortly after product installation or upgrade, potentially allowed an attacker to render ESET’s security product inoperable, provided non-default preconditions were met.

Data is provided by the National Vulnerability Database (NVD)
EsetInternet Security Version < 17.2.7.0
EsetNod32 Version < 17.2.7.0
EsetSecurity SwEditionultimate Version < 17.2.7.0
EsetSmart Security SwEditionpremium Version < 17.2.7.0
EsetEndpoint Antivirus SwPlatformwindows Version < 11.1.2039.0
EsetEndpoint Security SwPlatformwindows Version < 11.1.2039.0
EsetServer Security SwPlatformwindows_server Version < 11.0.12012.0
EsetMail Security SwPlatformexchange_server Version <= 11.0.10008.0
EsetMail Security Version- SwPlatformdomino
EsetSecurity SwPlatformsharepoint_server Version < 11.0.15004.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.08% 0.241
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
security@eset.com 6.1 1.8 4.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
CWE-276 Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.