Impact
A flaw in macOS versions of ESET Cyber Security and ESET Endpoint Security permits an attacker who can execute code locally to create or overwrite an arbitrary file with content fully under their control. The CVE description does not state the consequences of executing that file; based on common risk scenarios, it is inferred that such a file could be used to compromise system integrity or achieve code execution, but this is not explicitly documented in the advisory.
Affected Systems
ESET Cyber Security for macOS and ESET Endpoint Security for macOS are affected. Specific vulnerable releases are not listed, so all currently deployed versions should be considered at risk until ESET issues a patch.
Risk and Exploitability
The CVSS score of 8.5 reflects a high severity flaw, while the EPSS score of less than 1% indicates that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Attackers would need local access, meaning the threat is limited to users who already have some privilege on the machine. Based on the description, it is inferred that the attacker must be physically present or able to run code on the same machine to exploit the flaw. Even with the low exploitation probability, the high severity warrants rapid remediation.
OpenCVE Enrichment