Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2014-4973


The ESET Personal Firewall NDIS filter (EpFwNdis.sys) driver in the Firewall Module Build 1183 (20140214) and earlier in ESET Smart Security and ESET Endpoint Security products 5.0 through 7.0 allows local users to gain privileges via a crafted argument to a 0x830020CC IOCTL call.


Published

2014-09-23T15:55:06.480

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 6.9 (MEDIUM)

CVSSv2 Vector

AV:L/AC:M/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.4

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application eset smart_security 5.0.94 Yes
Application eset smart_security 5.0.95 Yes
Application eset smart_security 5.2.9 Yes
Application eset smart_security 5.2.15 Yes
Application eset smart_security 6.0.306 Yes
Application eset smart_security 6.0.308 Yes
Application eset smart_security 6.0.314 Yes
Application eset smart_security 6.0.316 Yes
Application eset endpoint_security 5.0.2113 Yes
Application eset endpoint_security 5.0.2122 Yes
Application eset endpoint_security 5.0.2126 Yes
Application eset endpoint_security 5.0.2214 Yes
Application eset endpoint_security 5.0.2225 Yes
Application eset endpoint_security 5.0.2228 Yes

References