Link following in Eset products - CVE-2024-0353
Published: February 20, 2024
Vulnerability identifier: #VU86629
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-0353
CWE-ID: CWE-59
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a link following issue within the ESET Service. A local user can abuse the service to delete a file, which leads to security restrictions bypass and privilege escalation.
Affected software
ESET Endpoint Antivirus for Windows
ESET NOD32 Antivirus
ESET Endpoint Security for Windows
ESET Security Ultimate
ESET Smart Security Premium
ESET Internet Security
ESET File Security for Microsoft Azure
ESET File Security for Microsoft Windows Server
ESET Mail Security for Microsoft Exchange Server
ESET Mail Security for IBM Domino
ESET Security for Microsoft SharePoint Server
ESET NOD32 Antivirus
ESET Endpoint Security for Windows
ESET Security Ultimate
ESET Smart Security Premium
ESET Internet Security
ESET File Security for Microsoft Azure
ESET File Security for Microsoft Windows Server
ESET Mail Security for Microsoft Exchange Server
ESET Mail Security for IBM Domino
ESET Security for Microsoft SharePoint Server
How to mitigate CVE-2024-0353
Install updates from vendor's website.
ESET Endpoint Antivirus for Windows - addressed in versions 8.1.2062.0, 9.1.2071.0, 10.0.2052.0, 10.1.2063.0, 11.0.2032.0
ESET File Security for Microsoft Windows Server - addressed in versions 7.3.12013.0, 8.0.12016.0, 9.0.12019.0, 10.0.12015.0
ESET NOD32 Antivirus - update to 17.0.10.0
ESET Endpoint Security for Windows - addressed in versions 8.1.2062.0, 9.1.2071.0, 10.0.2052.0, 10.1.2063.0, 11.0.2032.0
ESET Mail Security for Microsoft Exchange Server - addressed in versions 7.3.10018.0, 8.0.10024.0, 9.0.10012.0, 10.0.10018.0, 10.1.10014.0
ESET Mail Security for IBM Domino - addressed in versions 7.3.14006.0, 8.0.14014.0, 9.0.14008.0, 10.0.14007.0
ESET Security Ultimate - update to 17.0.10.0
ESET Security for Microsoft SharePoint Server - addressed in versions 7.3.15006.0, 8.0.15012.0, 9.0.15006.0, 10.0.15005.0
ESET Smart Security Premium - update to 17.0.10.0
ESET Internet Security - update to 17.0.10.0
ESET File Security for Microsoft Windows Server - addressed in versions 7.3.12013.0, 8.0.12016.0, 9.0.12019.0, 10.0.12015.0
ESET NOD32 Antivirus - update to 17.0.10.0
ESET Endpoint Security for Windows - addressed in versions 8.1.2062.0, 9.1.2071.0, 10.0.2052.0, 10.1.2063.0, 11.0.2032.0
ESET Mail Security for Microsoft Exchange Server - addressed in versions 7.3.10018.0, 8.0.10024.0, 9.0.10012.0, 10.0.10018.0, 10.1.10014.0
ESET Mail Security for IBM Domino - addressed in versions 7.3.14006.0, 8.0.14014.0, 9.0.14008.0, 10.0.14007.0
ESET Security Ultimate - update to 17.0.10.0
ESET Security for Microsoft SharePoint Server - addressed in versions 7.3.15006.0, 8.0.15012.0, 9.0.15006.0, 10.0.15005.0
ESET Smart Security Premium - update to 17.0.10.0
ESET Internet Security - update to 17.0.10.0