PT-2022-2607 · Eset · Eset Security For Microsoft Sharepoint Server+8

Published

2022-05-09

·

Updated

2022-05-19

·

CVE-2021-37851

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ESET NOD32 Antivirus versions 11.2 through 15.1.11.0 ESET Internet Security versions 11.2 through 15.1.11.0 ESET Smart Security Premium versions 11.2 through 15.1.11.0 ESET Endpoint Antivirus versions 6.0 through 9.0.2045.0 ESET Endpoint Security versions 6.0 through 9.0.2045.0 ESET Server Security for Microsoft Windows Server versions 8.0 through 9.0.12011.0 ESET File Security for Microsoft Windows Server version 8.0.12012.0 ESET Mail Security for Microsoft Exchange Server versions 6.0 through 8.0.10019.0 ESET Mail Security for IBM Domino versions 6.0 through 8.0.14010.0 ESET Security for Microsoft SharePoint Server versions 6.0 through 8.0.15008.0
Description The issue is related to the repair feature of the installer in ESET products, allowing a user logged into the system to exploit it and run malicious code with higher privileges. This is due to incorrect handling of insufficient permissions or privileges. The exploitation of this issue may allow an attacker to execute arbitrary code.
Recommendations For ESET NOD32 Antivirus versions 11.2 through 15.1.11.0, update to version 15.1.12.0 or later. For ESET Internet Security versions 11.2 through 15.1.11.0, update to version 15.1.12.0 or later. For ESET Smart Security Premium versions 11.2 through 15.1.11.0, update to version 15.1.12.0 or later. For ESET Endpoint Antivirus versions 6.0 through 9.0.2045.0, update to version 9.0.2046.0 or later. For ESET Endpoint Security versions 6.0 through 9.0.2045.0, update to version 9.0.2046.0 or later. For ESET Server Security for Microsoft Windows Server versions 8.0 through 9.0.12011.0, update to version 9.0.12012.0 or later. For ESET File Security for Microsoft Windows Server version 8.0.12012.0, update to a newer version. For ESET Mail Security for Microsoft Exchange Server versions 6.0 through 8.0.10019.0, update to version 8.0.10020.0 or later. For ESET Mail Security for IBM Domino versions 6.0 through 8.0.14010.0, update to version 8.0.14011.0 or later. For ESET Security for Microsoft SharePoint Server versions 6.0 through 8.0.15008.0, update to version 8.0.15009.0 or later.

Fix

Improper Handling of Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-03065
CVE-2021-37851

Affected Products

Eset Endpoint Antivirus
Eset Endpoint Security
Eset File Security For Microsoft Windows Server
Eset Internet Security
Eset Mail Security For Ibm Domino
Eset Mail Security For Microsoft Exchange Server
Eset Nod32 Antivirus
Eset Security For Microsoft Sharepoint Server
Eset Smart Security Premium