Man-in-the-Middle Vulnerability in ESET Endpoint Antivirus for macOS
CVE-2016-9892
5.9MEDIUM
What is CVE-2016-9892?
The esets_daemon service in ESET Endpoint Antivirus and Endpoint Security for macOS fails to validate X.509 certificates from the SSL server edf.eset.com. This flaw enables attackers to perform man-in-the-middle attacks, potentially allowing them to spoof the SSL server and send fabricated license activation responses using a self-signed certificate. Moreover, this vulnerability could be exploited in conjunction with other issues, enabling remote code execution with root privileges.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
