Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-9264


ESET Archive Support Module before 1296 allows virus-detection bypass via a crafted Compression Information Field in a ZIP archive. This affects versions before 1294 of Smart Security Premium, Internet Security, NOD32 Antivirus, Cyber Security Pro (macOS), Cyber Security (macOS), Mobile Security for Android, Smart TV Security, and NOD32 Antivirus 4 for Linux Desktop.


Published

2020-02-18T15:15:12.787

Last Modified

2024-11-21T05:40:18.097

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-436

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application eset cyber_security < 1296 Yes
Application eset cyber_security < 1296 Yes
Application eset internet_security < 1296 Yes
Application eset mobile_security < 1296 Yes
Application eset nod32_antivirus < 1296 Yes
Application eset nod32_antivirus 4 Yes
Application eset smart_security < 1296 Yes
Application eset smart_tv_security < 1296 Yes

References