Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-2847


During internal security analysis, a local privilege escalation vulnerability has been identified. On a machine with the affected ESET product installed, it was possible for a user with lower privileges due to improper privilege management to trigger actions with root privileges. ESET remedied this possible attack vector and has prepared new builds of its products that are no longer susceptible to this vulnerability.


Published

2023-06-15T08:15:09.150

Last Modified

2024-11-21T07:59:24.787

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-269
  • Type: Primary
    CWE-269

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application eset cyber_security < 7.3.3700.0 Yes
Application eset endpoint_antivirus < 8.1.12.0 Yes
Application eset endpoint_antivirus < 7.3.3600.0 Yes
Application eset endpoint_antivirus < 9.0.10.0 Yes
Application eset endpoint_antivirus < 9.1.11.0 Yes
Application eset server_security < 8.1.823.0 Yes
Application eset server_security < 9.0.466.0 Yes
Application eset server_security < 9.1.98.0 Yes

References