PT-2025-15185 · Eset · Eset Command Line Scanner
Published
2025-01-21
·
Updated
2025-11-25
·
CVE-2024-11859
CVSS v4.0
8.4
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ESET Command Line Scanner (affected versions not specified)
Description
The ESET Command Line Scanner contains a DLL search order hijacking issue related to the loading of the
version.dll library. This allows an attacker with administrator privileges to load a malicious dynamic-link library and execute its code. The ToddyCat APT group has been actively exploiting this issue, deploying malware such as TCESB, by replacing the legitimate version.dll with a malicious one. TCESB utilizes techniques to bypass security measures, including disabling security notifications and exploiting vulnerable drivers to gain kernel-level access. The malware is capable of stealing Outlook emails, browser credentials, and Microsoft 365 access tokens. The exploitation involves DLL proxying, where the malicious DLL exports the functions of the legitimate DLL while executing malicious code in the background. The attackers are also using tools like TCSectorCopy to access corporate email and SharpTokenFinder to obtain authentication tokens.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Eset Command Line Scanner