CVE Vulnerabilities

CVE-2024-0353

Improper Privilege Management

Published: Feb 15, 2024 | Modified: Jan 23, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Local privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to delete files without having proper permission.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Endpoint_antivirus Eset * 8.1.2062.0 (excluding)
Endpoint_antivirus Eset 9.0 (including) 9.1.2071.0 (excluding)
Endpoint_antivirus Eset 10.0 (including) 10.0.2052.0 (excluding)
Endpoint_antivirus Eset 10.1 (including) 10.1.2063.0 (excluding)
Endpoint_antivirus Eset 11.0 (including) 11.0.2032.0 (excluding)
Endpoint_security Eset * 8.1.2062.0 (excluding)
Endpoint_security Eset 9.0 (including) 9.1.2071.0 (excluding)
Endpoint_security Eset 10.0 (including) 10.0.2052.0 (excluding)
Endpoint_security Eset 10.1 (including) 10.1.2063.0 (excluding)
Endpoint_security Eset 11.0 (including) 11.0.2032.0 (excluding)
File_security Eset * *
Internet_security Eset * 17.0.10.0 (excluding)
Mail_security Eset * 7.3.10018.0 (excluding)
Mail_security Eset * 7.3.14006.0 (excluding)
Mail_security Eset 8.0 (including) 8.0.10024.0 (excluding)
Mail_security Eset 8.0 (including) 8.0.14014.0 (excluding)
Mail_security Eset 9.0 (including) 9.0.10012.0 (excluding)
Mail_security Eset 9.0 (including) 9.0.14008.0 (excluding)
Mail_security Eset 10.0 (including) 10.0.10018.0 (excluding)
Mail_security Eset 10.0 (including) 10.0.14007.0 (excluding)
Mail_security Eset 10.1 (including) 10.1.10014.0 (excluding)
Nod32_antivirus Eset * 17.0.10.0 (excluding)
Security Eset * 7.3.15006.0 (excluding)
Security Eset * 17.0.10.0 (excluding)
Security Eset 8.0 (including) 8.0.15012.0 (excluding)
Security Eset 9.0 (including) 9.0.15006.0 (excluding)
Security Eset 10.0 (including) 10.0.15005.0 (excluding)
Server_security Eset * 7.3.12013.0 (excluding)
Server_security Eset 8.0 (including) 8.0.12016.0 (excluding)
Server_security Eset 9.0 (including) 9.0.12019.0 (excluding)
Server_security Eset 10.0 (including) 10.0.12015.0 (excluding)
Smart_security Eset * 17.0.10.0 (excluding)

Potential Mitigations

References