CVE-2024-11859 is a high-severity DLL Search Order Hijacking vulnerability (CVSS 8.4) that allowed an attacker with administrator privileges to load and execute malicious code. While specific affected products are not listed in the provided data, media coverage indicates it was exploited in ESET antivirus products. The attack requires local access and low privileges, but can lead to high impact on confidentiality and integrity. Although no public exploit code is available, the vulnerability has been actively exploited in the wild, as evidenced by community discussions and media reports detailing its abuse by threat actors like ToddyCat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| ESET, Spol. S R.O. | ESET Endpoint Antivirus For Windows | >= 0, <= 11.1.2053.2, >= 0, <= 12.0.2038.0CNA affecteddefault unaffected | |
| ESET, Spol. S R.O. | ESET Endpoint Security For Windows | >= 0, <= 11.1.2053.2, >= 0, <= 12.0.2038.0CNA affecteddefault unaffected | |
| ESET, Spol. S R.O. | ESET Internet Security | >= 0, <= 18.0.12.0CNA affecteddefault unaffected | |
| ESET, Spol. S R.O. | ESET Mail Security For Microsoft Exchange Server | >= 0, <= 10.1.10014.0, >= 0, <= 11.0.10008.0, >= 0, <= 11.1.10008.0CNA affecteddefault unaffected | |
| ESET, Spol. S R.O. | ESET NOD32 Antivirus | >= 0, <= 18.0.12.0CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.