ESET Security Products for Windows
by Eset
CVEs (9)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-11859 | Hig | 0.55 | — | 0.02 | Apr 7, 2025 | DLL Search Order Hijacking vulnerability potentially allowed an attacker with administrator privileges to load a malicious dynamic-link library and execute its code. | ||
| CVE-2024-0353 | Hig | 0.51 | 7.8 | 0.01 | Feb 15, 2024 | Local privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to delete files without having proper permission. | ||
| CVE-2021-37852 | Hig | 0.51 | 7.8 | 0.01 | Feb 9, 2022 | ESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attacker to escalate privileges in the context of NT AUTHORITY\SYSTEM. | ||
| CVE-2023-5594 | Hig | 0.49 | 7.5 | 0.00 | Dec 21, 2023 | Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or SHA1 algorithm as trusted. | ||
| CVE-2025-4952 | Med | 0.44 | — | 0.00 | Oct 31, 2025 | Tampering of the registry entries might have led to preventing the ESET security products from starting correctly on the next system startup or to unauthorized changes in the product's configuration. | ||
| CVE-2025-5028 | Med | 0.44 | — | 0.00 | Jul 11, 2025 | Installation file of ESET security products on Windows allow an attacker to misuse to delete an arbitrary file without having the permissions to do so. | ||
| CVE-2024-6654 | Med | 0.44 | — | 0.00 | Sep 27, 2024 | Products for macOS enables a user logged on to the system to perform a denial-of-service attack, which could be misused to disable the protection of the ESET security product and cause general system slow-down. | ||
| CVE-2024-3779 | Med | 0.40 | 6.1 | 0.00 | Jul 16, 2024 | Denial of service vulnerability present shortly after product installation or upgrade, potentially allowed an attacker to render ESET’s security product inoperable, provided non-default preconditions were met. | ||
| CVE-2025-2425 | Med | 0.33 | — | 0.00 | Jul 18, 2025 | Time-of-check to time-of-use race condition vulnerability potentially allowed an attacker to use the installed ESET security software to clear the content of an arbitrary file on the file system. |
- risk 0.55cvss —epss 0.02
DLL Search Order Hijacking vulnerability potentially allowed an attacker with administrator privileges to load a malicious dynamic-link library and execute its code.
- risk 0.51cvss 7.8epss 0.01
Local privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to delete files without having proper permission.
- risk 0.51cvss 7.8epss 0.01
ESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attacker to escalate privileges in the context of NT AUTHORITY\SYSTEM.
- risk 0.49cvss 7.5epss 0.00
Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or SHA1 algorithm as trusted.
- risk 0.44cvss —epss 0.00
Tampering of the registry entries might have led to preventing the ESET security products from starting correctly on the next system startup or to unauthorized changes in the product's configuration.
- risk 0.44cvss —epss 0.00
Installation file of ESET security products on Windows allow an attacker to misuse to delete an arbitrary file without having the permissions to do so.
- risk 0.44cvss —epss 0.00
Products for macOS enables a user logged on to the system to perform a denial-of-service attack, which could be misused to disable the protection of the ESET security product and cause general system slow-down.
- risk 0.40cvss 6.1epss 0.00
Denial of service vulnerability present shortly after product installation or upgrade, potentially allowed an attacker to render ESET’s security product inoperable, provided non-default preconditions were met.
- risk 0.33cvss —epss 0.00
Time-of-check to time-of-use race condition vulnerability potentially allowed an attacker to use the installed ESET security software to clear the content of an arbitrary file on the file system.