PT-2021-2195 · Eset · Eset Nod32 Antivirus Business Edition+12
Ilias Dimopoulos
·
Published
2021-01-21
·
Updated
2021-02-02
·
CVE-2020-26941
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
ESET NOD32 Antivirus versions 13.2 and lower
ESET Internet Security versions 13.2 and lower
ESET Smart Security versions 13.2 and lower
ESET Smart Security Premium versions 13.2 and lower
ESET Endpoint Antivirus versions 7.3 and lower
ESET Endpoint Security versions 7.3 and lower
ESET NOD32 Antivirus Business Edition versions 7.3 and lower
ESET Smart Security Business Edition versions 7.3 and lower
ESET File Security for Microsoft Windows Server versions 7.2 and lower
ESET Mail Security for Microsoft Exchange Server versions 7.2 and lower
ESET Mail Security for IBM Domino versions 7.2 and lower
ESET Security for Kerio versions 7.2 and lower
ESET Security for Microsoft SharePoint Server versions 7.2 and lower
Description:
A local (authenticated) low-privileged user can exploit a behavior in an ESET installer to achieve arbitrary file overwrite (deletion) of any file via a symlink, due to insecure permissions. The possibility of exploiting this issue is limited and can only take place during the installation phase of ESET products. Furthermore, exploitation can only succeed when Self-Defense is disabled.
Recommendations:
For ESET NOD32 Antivirus versions 13.2 and lower, update to a version higher than 13.2.
For ESET Internet Security versions 13.2 and lower, update to a version higher than 13.2.
For ESET Smart Security versions 13.2 and lower, update to a version higher than 13.2.
For ESET Smart Security Premium versions 13.2 and lower, update to a version higher than 13.2.
For ESET Endpoint Antivirus versions 7.3 and lower, update to a version higher than 7.3.
For ESET Endpoint Security versions 7.3 and lower, update to a version higher than 7.3.
For ESET NOD32 Antivirus Business Edition versions 7.3 and lower, update to a version higher than 7.3.
For ESET Smart Security Business Edition versions 7.3 and lower, update to a version higher than 7.3.
For ESET File Security for Microsoft Windows Server versions 7.2 and lower, update to a version higher than 7.2.
For ESET Mail Security for Microsoft Exchange Server versions 7.2 and lower, update to a version higher than 7.2.
For ESET Mail Security for IBM Domino versions 7.2 and lower, update to a version higher than 7.2.
For ESET Security for Kerio versions 7.2 and lower, update to a version higher than 7.2.
For ESET Security for Microsoft SharePoint Server versions 7.2 and lower, update to a version higher than 7.2.
As a temporary workaround, consider enabling Self-Defense to prevent exploitation.
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Eset Endpoint Antivirus
Eset Endpoint Security
Eset File Security For Microsoft Windows Server
Eset Internet Security
Eset Mail Security For Ibm Domino
Eset Mail Security For Microsoft Exchange Server
Eset Nod32 Antivirus
Eset Nod32 Antivirus Business Edition
Eset Security For Kerio
Eset Security For Microsoft Sharepoint Server
Eset Smart Security
Eset Smart Security Business Edition
Eset Smart Security Premium