Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-7043


Unquoted service path in ESET products allows to drop a prepared program to a specific location and run on boot with the NT AUTHORITY\NetworkService permissions.


Published

2024-01-31T13:15:10.147

Last Modified

2024-11-21T08:45:06.820

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 3.3 (LOW)

Weaknesses
  • Type: Secondary
    CWE-428
  • Type: Primary
    CWE-428

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application eset endpoint_antivirus < 11.0.2032.0 Yes
Application eset endpoint_security < 11.0.2032.0 Yes
Application eset internet_security < 17.0.15.0 Yes
Application eset mail_security 10.1.10012.0 Yes
Application eset nod32_antivirus < 17.0.15.0 Yes
Application eset smart_security_premium < 17.0.15.0 Yes

References