Unquoted service path in ESET products allows to drop a prepared program to a specific location and run on boot with the NT AUTHORITY\NetworkService permissions.
2024-01-31T13:15:10.147
2024-11-21T08:45:06.820
Modified
CVSSv3.1: 3.3 (LOW)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | eset | endpoint_antivirus | < 11.0.2032.0 | Yes |
Application | eset | endpoint_security | < 11.0.2032.0 | Yes |
Application | eset | internet_security | < 17.0.15.0 | Yes |
Application | eset | mail_security | 10.1.10012.0 | Yes |
Application | eset | nod32_antivirus | < 17.0.15.0 | Yes |
Application | eset | smart_security_premium | < 17.0.15.0 | Yes |