Vulnerabilities > Eset > Internet Security > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-01-31 CVE-2023-7043 Unquoted Search Path or Element vulnerability in Eset products
Unquoted service path in ESET products allows to drop a prepared program to a specific location and run on boot with the NT AUTHORITY\NetworkService permissions.
local
low complexity
eset CWE-428
5.5
2020-04-29 CVE-2020-11446 Improper Privilege Management vulnerability in Eset products
ESET Antivirus and Antispyware Module module 1553 through 1560 allows a user with limited access rights to create hard links in some ESET directories and then force the product to write through these links into files that would normally not be write-able by the user, thus achieving privilege escalation.
local
low complexity
eset CWE-269
4.6
2020-03-06 CVE-2020-10193 Improper Input Validation vulnerability in Eset products
ESET Archive Support Module before 1294 allows virus-detection bypass via crafted RAR Compression Information in an archive.
network
low complexity
eset CWE-20
5.0
2020-02-18 CVE-2020-9264 Improper Input Validation vulnerability in Eset products
ESET Archive Support Module before 1296 allows virus-detection bypass via a crafted Compression Information Field in a ZIP archive.
network
eset CWE-20
4.3