Impact
The flaw permits a local attacker to run code with elevated privileges, enabling full system compromise. Listed as CWE-269, privilege escalation, the attacker could gain control over the operating system, access sensitive data, install malware, or tamper with system configurations.
Affected Systems
ESET Cyber Security for macOS and ESET Endpoint Security for macOS from ESET spol. s.r.o. No specific versions are disclosed in the advisory.
Risk and Exploitability
The CVSS score of 8.5 reflects a severe risk. The EPSS indicates an exploitation probability of less than 1%, and the flaw is not present in the CISA KEV list. Exploitation requires local access on the affected macOS system; thus the threat surface is somewhat limited, but the potential impact remains high for compromised machines.
OpenCVE Enrichment