ESET File Operations Vulnerability Allows Deletion of Files Without Permission
CVE-2024-0353

7.8HIGH

Key Information:

What is CVE-2024-0353?

A local privilege escalation vulnerability has been identified in ESET products for Windows, which may allow an attacker with limited permissions to exploit file operation functionalities. This exploitation can lead to unauthorized deletions of files, significantly compromising the integrity and security of user data. It is crucial for users of affected ESET products to apply the necessary patches to safeguard against potential misuse of these vulnerabilities.

Affected Version(s)

ESET Endpoint Antivirus for Windows 0 <= 10.1.2058.0

ESET Endpoint Antivirus for Windows 0 <= 10.0.2049.0

ESET Endpoint Antivirus for Windows 0 <= 9.1.2066.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.