CVE Vulnerabilities

CVE-2019-16519

Improper Privilege Management

Published: Oct 14, 2019 | Modified: Jan 01, 2022
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

ESET Cyber Security 6.7.900.0 for macOS allows a local attacker to execute unauthorized commands as root by abusing an undocumented feature in scheduled tasks.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Cyber_security Eset * 6.7.900.0 (including)
Endpoint_antivirus Eset * 6.7.900.0 (including)
Endpoint_security Eset * 6.7.900.0 (including)

Potential Mitigations

References