Home/Product/eset smart security
Product

eset smart security

18 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-3779
< 17.2.7.0
Denial of service vulnerability present shortly after product installation or upgrade, potentially allowed an attacker to render E
6.1MEDIUM
CVE-2024-0353
< 17.0.10.0
Local privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to delete files withou
7.8HIGH
CVE-2023-5594
all versions
Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate sig
7.5HIGH
CVE-2023-3160
all versions
The vulnerability potentially allows an attacker to misuse ESET’s file operations during the module update to delete or move fil
7.8HIGH
CVE-2021-37851
>= 11.2 and < 15.1.12.0
Local privilege escalation in Windows products of ESET allows user who is logged into the system to exploit repair feature of the
7.3HIGH
CVE-2022-27167
>= 11.2 and < 15.1.12.0
Privilege escalation vulnerability in Windows products of ESET, spol. s r.o. allows attacker to exploit "Repair" and "Uninstall" f
7.1HIGH
CVE-2021-37852
>= 10.0.337.1 and <= 15.0.18.0
ESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attacker to esca
7.8HIGH
CVE-2020-26941
<= 13.2
A local (authenticated) low-privileged user can exploit a behavior in an ESET installer to achieve arbitrary file overwrite (delet
5.5MEDIUM
CVE-2020-11446
all versions
ESET Antivirus and Antispyware Module 1553 through 1560 allows a user with limited access rights to create hard links in so
7.8HIGH
CVE-2020-10193
< 1294
ESET Archive Support Module before 1294 allows virus-detection bypass via crafted RAR Compression Information in an archive. This
7.5HIGH
CVE-2020-10180
< 1294
The ESET AV parsing engine allows virus-detection bypass via a crafted BZ2 Checksum field in an archive. This affects versions bef
9.8CRITICAL
CVE-2020-9264
< 1296
ESET Archive Support Module before 1296 allows virus-detection bypass via a crafted Compression Information Field in a ZIP archive
5.5MEDIUM
CVE-2018-0649
all versions
Untrusted search path vulnerability in the installers of multiple Canon IT Solutions Inc. software programs (ESET Smart Security P
7.8HIGH
CVE-2014-4973
all versions
The ESET Personal Firewall NDIS filter (EpFwNdis.sys) driver in the Firewall Module Build 1183 (20140214) and earlier in ESET Smar
CVE-2010-5160
all versions
Race condition in ESET Smart Security 4.2.35.3 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute d
4.5MEDIUM
CVE-2008-7107
all versions
easdrv.sys in ESET Smart Security 3.0.667.0 allows local users to cause a denial of service (crash) via a crafted IOCTL 0x222003 r
CVE-2008-5724
<= 3.0.672
The Personal Firewall driver (aka epfw.sys) 3.0.672.0 and earlier in ESET Smart Security 3.0.672 and earlier allows local users to
CVE-2008-5527
all versions
ESET Smart Security, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML docu
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin