PT-2021-2195 · Eset · Eset Nod32 Antivirus Business Edition+12

Ilias Dimopoulos

·

Published

2021-01-21

·

Updated

2021-02-02

·

CVE-2020-26941

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: ESET NOD32 Antivirus versions 13.2 and lower ESET Internet Security versions 13.2 and lower ESET Smart Security versions 13.2 and lower ESET Smart Security Premium versions 13.2 and lower ESET Endpoint Antivirus versions 7.3 and lower ESET Endpoint Security versions 7.3 and lower ESET NOD32 Antivirus Business Edition versions 7.3 and lower ESET Smart Security Business Edition versions 7.3 and lower ESET File Security for Microsoft Windows Server versions 7.2 and lower ESET Mail Security for Microsoft Exchange Server versions 7.2 and lower ESET Mail Security for IBM Domino versions 7.2 and lower ESET Security for Kerio versions 7.2 and lower ESET Security for Microsoft SharePoint Server versions 7.2 and lower
Description: A local (authenticated) low-privileged user can exploit a behavior in an ESET installer to achieve arbitrary file overwrite (deletion) of any file via a symlink, due to insecure permissions. The possibility of exploiting this issue is limited and can only take place during the installation phase of ESET products. Furthermore, exploitation can only succeed when Self-Defense is disabled.
Recommendations: For ESET NOD32 Antivirus versions 13.2 and lower, update to a version higher than 13.2. For ESET Internet Security versions 13.2 and lower, update to a version higher than 13.2. For ESET Smart Security versions 13.2 and lower, update to a version higher than 13.2. For ESET Smart Security Premium versions 13.2 and lower, update to a version higher than 13.2. For ESET Endpoint Antivirus versions 7.3 and lower, update to a version higher than 7.3. For ESET Endpoint Security versions 7.3 and lower, update to a version higher than 7.3. For ESET NOD32 Antivirus Business Edition versions 7.3 and lower, update to a version higher than 7.3. For ESET Smart Security Business Edition versions 7.3 and lower, update to a version higher than 7.3. For ESET File Security for Microsoft Windows Server versions 7.2 and lower, update to a version higher than 7.2. For ESET Mail Security for Microsoft Exchange Server versions 7.2 and lower, update to a version higher than 7.2. For ESET Mail Security for IBM Domino versions 7.2 and lower, update to a version higher than 7.2. For ESET Security for Kerio versions 7.2 and lower, update to a version higher than 7.2. For ESET Security for Microsoft SharePoint Server versions 7.2 and lower, update to a version higher than 7.2. As a temporary workaround, consider enabling Self-Defense to prevent exploitation.

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-01104
CVE-2020-26941

Affected Products

Eset Endpoint Antivirus
Eset Endpoint Security
Eset File Security For Microsoft Windows Server
Eset Internet Security
Eset Mail Security For Ibm Domino
Eset Mail Security For Microsoft Exchange Server
Eset Nod32 Antivirus
Eset Nod32 Antivirus Business Edition
Eset Security For Kerio
Eset Security For Microsoft Sharepoint Server
Eset Smart Security
Eset Smart Security Business Edition
Eset Smart Security Premium