5.5

CVE-2024-3779

Denial of Service in ESET products for Windows

Denial of service vulnerability present shortly after product installation or upgrade, potentially allowed an attacker to render ESET’s security product inoperable, provided non-default preconditions were met.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Eset ≫ Internet Security Version < 17.2.7.0
Eset ≫ Nod32 Version < 17.2.7.0
Eset ≫ Security SwEdition ultimate Version < 17.2.7.0
Eset ≫ Smart Security SwEdition premium Version < 17.2.7.0
Eset ≫ Endpoint Antivirus SwPlatform windows Version < 11.1.2039.0
Eset ≫ Endpoint Security SwPlatform windows Version < 11.1.2039.0
Eset ≫ Server Security SwPlatform windows_server Version < 11.0.12012.0
Eset ≫ Mail Security SwPlatform exchange_server Version <= 11.0.10008.0
Eset ≫ Mail Security Version - SwPlatform domino
Eset ≫ Security SwPlatform sharepoint_server Version < 11.0.15004.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.103
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
security@eset.com 6.1 1.8 4.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
CWE-276 Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.