The vulnerability potentially allowed an attacker to misuse ESET’s file operations during the removal of a detected file on the Windows operating system to delete files without having proper permissions to do so.
History

Fri, 27 Sep 2024 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Eset
Eset endpoint Antivirus
Eset endpoint Security
Eset file Security
Eset internet Security
Eset mail Security
Eset nod32 Antivirus
Eset safe Server
Eset security
Eset security Ultimate
Eset server Security
Eset small Business Security
Eset smart Security
CPEs cpe:2.3:a:eset:endpoint_antivirus:*:*:*:*:*:*:*:*
cpe:2.3:a:eset:endpoint_security:-:*:*:*:*:windows:*:*
cpe:2.3:a:eset:file_security:-:*:*:*:*:azure:*:*
cpe:2.3:a:eset:internet_security:*:*:*:*:*:*:*:*
cpe:2.3:a:eset:mail_security:-:*:*:*:*:domino:*:*
cpe:2.3:a:eset:mail_security:-:*:*:*:*:exchange_server:*:*
cpe:2.3:a:eset:nod32_antivirus:*:*:*:*:*:*:*:*
cpe:2.3:a:eset:safe_server:-:*:*:*:*:*:*:*
cpe:2.3:a:eset:security:-:*:*:*:*:sharepoint_server:*:*
cpe:2.3:a:eset:security_ultimate:*:*:*:*:*:*:*:*
cpe:2.3:a:eset:server_security:-:*:*:*:*:windows_server:*:*
cpe:2.3:a:eset:small_business_security:*:*:*:*:*:*:*:*
cpe:2.3:a:eset:smart_security:-:*:*:*:premium:*:*:*
Vendors & Products Eset
Eset endpoint Antivirus
Eset endpoint Security
Eset file Security
Eset internet Security
Eset mail Security
Eset nod32 Antivirus
Eset safe Server
Eset security
Eset security Ultimate
Eset server Security
Eset small Business Security
Eset smart Security
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 27 Sep 2024 07:15:00 +0000

Type Values Removed Values Added
Description The vulnerability potentially allowed an attacker to misuse ESET’s file operations during the removal of a detected file on the Windows operating system to delete files without having proper permissions to do so.
Title Local privilege escalation in ESET products for Windows
Weaknesses CWE-1386
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ESET

Published: 2024-09-27T07:02:28.931Z

Updated: 2024-09-27T18:54:39.099Z

Reserved: 2024-08-02T07:12:41.358Z

Link: CVE-2024-7400

cve-icon Vulnrichment

Updated: 2024-09-27T18:54:31.575Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-27T07:15:03.387

Modified: 2024-09-30T12:46:20.237

Link: CVE-2024-7400

cve-icon Redhat

No data.