CVE-2020-26941 describes a local privilege escalation vulnerability in ESET products, allowing an authenticated low-privileged user to achieve arbitrary file overwrite (deletion) via a symlink during the installation phase. This affects various ESET consumer and business products, including ESET NOD32 Antivirus, ESET Internet Security, and ESET Endpoint Security, across specific versions. The vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low complexity, requiring a low-privileged user, and resulting in high integrity impact (file deletion). Exploitation is limited to the installation phase and requires ESET's Self-Defense feature to be disabled. There is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.3CPE matchmatch criteria | cpe:2.3:a:eset:endpoint_antivirus:*:*:*:*:*:-:*:* | ||
<= 7.3CPE matchmatch criteria | cpe:2.3:a:eset:endpoint_security:*:*:*:*:*:*:*:* | ||
<= 7.2CPE matchmatch criteria | cpe:2.3:a:eset:file_security:*:*:*:*:*:windows_server:*:* | ||
<= 13.2CPE matchmatch criteria | cpe:2.3:a:eset:internet_security:*:*:*:*:*:*:*:* | ||
1294CPE matchmatch criteria | cpe:2.3:a:eset:internet_security:1294:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.