Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-11446


ESET Antivirus and Antispyware Module module 1553 through 1560 allows a user with limited access rights to create hard links in some ESET directories and then force the product to write through these links into files that would normally not be write-able by the user, thus achieving privilege escalation.


Published

2020-04-29T14:15:17.607

Last Modified

2024-11-21T04:57:56.070

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.9

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-59

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application eset antivirus_and_antispyware ≤ 1560 Yes
Application eset endpoint_antivirus - Yes
Application eset endpoint_security - Yes
Application eset file_security - Yes
Application eset internet_security - Yes
Application eset mail_security - Yes
Application eset mail_security - Yes
Application eset mail_security - Yes
Application eset mail_security - Yes
Application eset nod32_antivirus - Yes
Application eset nod32_antivirus - Yes
Application eset smart_security - Yes
Application eset smart_security - Yes
Application eset smart_security - Yes

References