VYPR

ESET Security Products for Windows

by Eset

CVEs (9)

  • CVE-2024-11859HigApr 7, 2025
    risk 0.55cvss epss 0.02

    DLL Search Order Hijacking vulnerability potentially allowed an attacker with administrator privileges to load a malicious dynamic-link library and execute its code.

  • CVE-2024-0353HigFeb 15, 2024
    risk 0.51cvss 7.8epss 0.01

    Local privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to delete files without having proper permission.

  • CVE-2021-37852HigFeb 9, 2022
    risk 0.51cvss 7.8epss 0.01

    ESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attacker to escalate privileges in the context of NT AUTHORITY\SYSTEM.

  • CVE-2023-5594HigDec 21, 2023
    risk 0.49cvss 7.5epss 0.00

    Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or SHA1 algorithm as trusted.

  • CVE-2025-4952MedOct 31, 2025
    risk 0.44cvss epss 0.00

    Tampering of the registry entries might have led to preventing the ESET security products from starting correctly on the next system startup or to unauthorized changes in the product's configuration.

  • CVE-2025-5028MedJul 11, 2025
    risk 0.44cvss epss 0.00

    Installation file of ESET security products on Windows allow an attacker to misuse to delete an arbitrary file without having the permissions to do so.

  • CVE-2024-6654MedSep 27, 2024
    risk 0.44cvss epss 0.00

    Products for macOS enables a user logged on to the system to perform a denial-of-service attack, which could be misused to disable the protection of the ESET security product and cause general system slow-down.

  • CVE-2024-3779MedJul 16, 2024
    risk 0.40cvss 6.1epss 0.00

    Denial of service vulnerability present shortly after product installation or upgrade, potentially allowed an attacker to render ESET’s security product inoperable, provided non-default preconditions were met.

  • CVE-2025-2425MedJul 18, 2025
    risk 0.33cvss epss 0.00

    Time-of-check to time-of-use race condition vulnerability potentially allowed an attacker to use the installed ESET security software to clear the content of an arbitrary file on the file system.