Local Privilege Escalation Vulnerability in ESET Antivirus by ESET
CVE-2020-11446

7.8HIGH

Key Information:

Vendor

Eset

Vendor
CVE Published:
29 April 2020

What is CVE-2020-11446?

A vulnerability in ESET Antivirus and Antispyware Module allows users with limited access rights to create hard links in specific ESET directories. This can permit these users to direct the antivirus software to write to files that are normally protected, thereby escalating their access privileges. This issue could potentially be exploited to perform unauthorized actions or access restricted data, underscoring the need for immediate updates and mitigations.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.