Home/Product/withsecure server security
Product

withsecure server security

30 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-3779
< 11.0.12012.0
Denial of service vulnerability present shortly after product installation or upgrade, potentially allowed an attacker to render E
6.1MEDIUM
CVE-2024-4454
all versions
WithSecure Elements Endpoint Protection Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local a
7.8HIGH
CVE-2024-0353
< 7.3.12013.0
Local privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to delete files withou
7.8HIGH
CVE-2024-23764
all versions
Certain WithSecure products allow Local Privilege Escalation. This affects WithSecure Client Security 15 and later, WithSecure Ser
6.7MEDIUM
CVE-2023-5594
>= 10.1
Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate sig
7.5HIGH
CVE-2023-49322
all versions
Certain WithSecure products allow a Denial of Service because there is an unpack handler crash that can lead to a scanning engine
7.5HIGH
CVE-2023-49321
all versions
Certain WithSecure products allow a Denial of Service because scanning a crafted file takes a long time, and causes the scanner to
5.3MEDIUM
CVE-2023-47172
>= 15
Certain WithSecure products allow Local Privilege Escalation. This affects WithSecure Client Security 15, WithSecure Server Securi
7.8HIGH
CVE-2023-47264
all versions
Certain WithSecure products have a buffer over-read whereby processing certain fuzz file types may cause a denial of service (DoS)
7.5HIGH
CVE-2023-47263
all versions
Certain WithSecure products allow a Denial of Service (DoS) in the antivirus engine when scanning a fuzzed PE32 file. This affects
7.5HIGH
CVE-2023-43767
all versions
Certain WithSecure products allow Denial of Service via the aepack archive unpack handler. This affects WithSecure Client Security
7.5HIGH
CVE-2023-43766
all versions
Certain WithSecure products allow Local privilege escalation via the lhz archive unpack handler. This affects WithSecure Client Se
7.8HIGH
CVE-2023-43765
all versions
Certain WithSecure products allow Denial of Service in the aeelf component. This affects WithSecure Client Security 15, WithSecure
7.5HIGH
CVE-2023-43761
all versions
Certain WithSecure products allow Denial of Service (infinite loop). This affects WithSecure Client Security 15, WithSecure Server
7.5HIGH
CVE-2023-43760
all versions
Certain WithSecure products allow Denial of Service via a fuzzed PE32 file. This affects WithSecure Client Security 15, WithSecure
7.5HIGH
CVE-2023-42525
all versions
Certain WithSecure products allow an infinite loop in a scanning engine via unspecified file types. This affects WithSecure Client
7.5HIGH
CVE-2023-42524
all versions
Certain WithSecure products allow an infinite loop in a scanning engine via unspecified file types. This affects WithSecure Client
7.5HIGH
CVE-2023-42523
all versions
Certain WithSecure products allow a remote crash of a scanning engine via unpacking of a PE file. This affects WithSecure Client S
7.5HIGH
CVE-2023-42522
all versions
Certain WithSecure products allow a remote crash of a scanning engine via processing of an import struct in a PE file. This affect
7.5HIGH
CVE-2023-42521
all versions
Certain WithSecure products allow a remote crash of a scanning engine via processing of a compressed file. This affects WithSecure
7.5HIGH
CVE-2023-42526
all versions
Certain WithSecure products allow a remote crash of a scanning engine via decompression of crafted data files. This affects WithSe
7.5HIGH
CVE-2023-42520
all versions
Certain WithSecure products allow a remote crash of a scanning engine via unpacking of crafted data files. This affects WithSecure
7.5HIGH
CVE-2023-3160
all versions
The vulnerability potentially allows an attacker to misuse ESET’s file operations during the module update to delete or move fil
7.8HIGH
CVE-2023-2847
< 8.1.823.0
During internal security analysis, a local privilege escalation vulnerability has been identified. On a machine with the affected
7.8HIGH
CVE-2021-37851
>= 6.0
Local privilege escalation in Windows products of ESET allows user who is logged into the system to exploit repair feature of the
7.3HIGH
CVE-2022-27167
>= 6.0
Privilege escalation vulnerability in Windows products of ESET, spol. s r.o. allows attacker to exploit "Repair" and "Uninstall" f
7.1HIGH
CVE-2021-44750
all versions
An arbitrary code execution vulnerability was found in the F-Secure Support Tool. A standard user can craft a special configuratio
6.4MEDIUM
CVE-2022-0615
>= 7.2.463.0 and <= 7.2.574.0
Use-after-free in eset_rtp kernel module used in ESET products for Linux allows potential attacker to trigger denial-of-service co
5.9MEDIUM
CVE-2021-37852
>= 7.0.12016.1002 and <= 7.2.12004.1000
ESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attacker to esca
7.8HIGH
CVE-2013-7369
all versions
SQL injection vulnerability in an unspecified DLL in the FSDBCom ActiveX control in F-Secure Anti-Virus for Microsoft Exchange Ser
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin