CVE-2023-2847
Local privilege escalation in ESET products for Linux and MacOS
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.8EPSS 0.1%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
15 Jun 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
During internal security analysis, a local privilege escalation vulnerability has been identified. On a machine with the affected ESET product installed, it was possible for a user with lower privileges due to improper privilege management to trigger actions with root privileges.
ESET remedied this possible attack vector and has prepared new builds of its products that are no longer susceptible to this vulnerability.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products
ESET · Cyber SecurityESET · Endpoint Antivirus for LinuxESET · Endpoint Antivirus for macOSESET · Server Security for LinuxWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://support.eset.com/en/ca8447