CVE-2014-4974 describes a local information disclosure vulnerability in the ESET Personal Firewall NDIS filter (EpFwNdis.sys) kernel mode driver, affecting ESET products versions 5.0 through 7.0. An attacker with local access could exploit this by crafting specific IOCTL calls to obtain sensitive information directly from kernel memory. With a CVSS score of 2.1 (AV:L/AC:L/Au:N/C:P/I:N/A:N), this vulnerability has low severity, requiring local access and low attack complexity, with the primary impact being confidentiality. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1183_\(20140214\)CPE matchmatch criteria | cpe:2.3:a:eset:personal_firewall_ndis_filter:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.