Vulnerabilities > Eset > Endpoint Antivirus > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-01-31 CVE-2023-7043 Unquoted Search Path or Element vulnerability in Eset products
Unquoted service path in ESET products allows to drop a prepared program to a specific location and run on boot with the NT AUTHORITY\NetworkService permissions.
local
low complexity
eset CWE-428
5.5
2020-04-29 CVE-2020-11446 Improper Privilege Management vulnerability in Eset products
ESET Antivirus and Antispyware Module module 1553 through 1560 allows a user with limited access rights to create hard links in some ESET directories and then force the product to write through these links into files that would normally not be write-able by the user, thus achieving privilege escalation.
local
low complexity
eset CWE-269
4.6
2017-03-02 CVE-2016-9892 Improper Certificate Validation vulnerability in Eset Endpoint Antivirus and Endpoint Security
The esets_daemon service in ESET Endpoint Antivirus for macOS before 6.4.168.0 and Endpoint Security for macOS before 6.4.168.0 does not properly verify X.509 certificates from the edf.eset.com SSL server, which allows man-in-the-middle attackers to spoof this server and provide crafted responses to license activation requests via a self-signed certificate.
network
eset CWE-295
4.3