CVE-2024-7400 describes a high-severity privilege escalation vulnerability in ESET’s Windows products. An attacker could exploit a flaw in ESET's file operations during malware removal to delete arbitrary files without requiring elevated permissions. This local attack, with low complexity, could lead to significant impact on confidentiality, integrity, and availability of the affected system. While no public exploit code or active exploitation has been observed, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| ESET, Spol. S R.O. | ESET Endpoint Antivirus | >= 0, <= 1250CNA affecteddefault unaffected | |
| ESET, Spol. S R.O. | ESET Endpoint Security For Windows | >= 0, <= 1250CNA affecteddefault unaffected | |
| ESET, Spol. S R.O. | ESET File Security For Microsoft Azure | >= 0, <= 1250CNA affecteddefault unaffected | |
| ESET, Spol. S R.O. | ESET Internet Security | >= 0, <= 1250CNA affecteddefault unaffected | |
| ESET, Spol. S R.O. | ESET Mail Security For IBM Domino | >= 0, <= 1250CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.