Improper Resource Shutdown or Release in Eset products - CVE-2021-37850

 

Improper Resource Shutdown or Release in Eset products - CVE-2021-37850

Published: October 29, 2021 / Updated: November 8, 2021


Vulnerability identifier: #VU57780
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-37850
CWE-ID: CWE-404
Exploitation vector: Local access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper resource shutdown or release. A local user can cause a denial of service condition on the target system.


Affected software

ESET Cyber Security
ESET Cyber Security Pro
ESET Endpoint Antivirus for macOS
ESET Endpoint Security for macOS

How to mitigate CVE-2021-37850

Install updates from vendor's website.

ESET Cyber Security - update to 6.11.2.0
ESET Cyber Security Pro - update to 6.11.2.0
ESET Endpoint Antivirus for macOS - update to 6.11.1.0
ESET Endpoint Security for macOS - update to 6.11.1.0

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins