5.1
CVE-2025-2425
- EPSS 0.02%
- Veröffentlicht 18.07.2025 09:20:52
- Zuletzt bearbeitet 22.07.2025 13:06:27
- Quelle security@eset.com
- Teams Watchlist Login
- Unerledigt Login
Time-of-check to time-of-use race condition vulnerability potentially allowed an attacker to use the installed ESET security software to clear the content of an arbitrary file on the file system.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerESET, spol. s.r.o
≫
Produkt
ESET NOD32 Antivirus
Default Statusunaffected
Version <=
18.1.13.0
Version
0
Status
affected
HerstellerESET, spol. s.r.o
≫
Produkt
ESET Internet Security
Default Statusunaffected
Version <=
18.1.13.0
Version
0
Status
affected
HerstellerESET, spol. s.r.o
≫
Produkt
ESET Smart Security Premium
Default Statusunaffected
Version <=
18.1.13.0
Version
0
Status
affected
HerstellerESET, spol. s.r.o
≫
Produkt
ESET Security Ultimate
Default Statusunaffected
Version <=
18.1.13.0
Version
0
Status
affected
HerstellerESET, spol. s.r.o
≫
Produkt
ESET Endpoint Antivirus for Windows
Default Statusunaffected
Version <=
12.0.2049.0
Version
0
Status
affected
Version <=
11.1.2059.0
Version
0
Status
affected
HerstellerESET, spol. s.r.o
≫
Produkt
ESET Endpoint Security for Windows
Default Statusunaffected
Version <=
12.0.2049.0
Version
0
Status
affected
Version <=
11.1.2059.0
Version
0
Status
affected
HerstellerESET, spol. s.r.o
≫
Produkt
ESET Small Business Security
Default Statusunaffected
Version <=
18.1.13.0
Version
0
Status
affected
HerstellerESET, spol. s.r.o
≫
Produkt
ESET Safe Server
Default Statusunaffected
Version <=
18.1.13.0
Version
0
Status
affected
HerstellerESET, spol. s.r.o
≫
Produkt
ESET Server Security for Windows Server
Default Statusunaffected
Version <=
12.0.12004.0
Version
0
Status
affected
Version <=
11.1.12009.1
Version
0
Status
affected
HerstellerESET, spol. s.r.o
≫
Produkt
ESET Mail Security for Microsoft Exchange Server
Default Statusunaffected
Version <=
12.0.10003.0
Version
0
Status
affected
Version <=
11.1.10011.0
Version
0
Status
affected
HerstellerESET, spol. s.r.o
≫
Produkt
ESET Security for Microsoft SharePoint Server
Default Statusunaffected
Version <=
12.0.15004.0
Version
0
Status
affected
Version <=
11.1.15003.0
Version
0
Status
affected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.02% | 0.026 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
security@eset.com | 5.1 | 0 | 0 |
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition
The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check. This can cause the product to perform invalid actions when the resource is in an unexpected state.