Endpoint Security

Vendor:

First CVE: Sep 23, 2014 · Active for 11 years

14
Total CVEs
More Total CVEs than 91% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Endpoint Security over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 23, 2014
11 years ago
Most Recent CVE
Jul 16, 2024
740 days ago

CVE Severity & Scoring

Endpoint Security14 CVEs
All CVEs352,713 CVEs
MediumHigh
Attack Vector
Local11 (78.6%)
Network2 (14.3%)
Unknown1 (7.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (85.7%)
High1 (7.1%)
Unknown1 (7.1%)
User Interaction
None13 (92.9%)
Unknown1 (7.1%)
Required0 (0.0%)
Privileges Required
Low11 (78.6%)
High0 (0.0%)
None2 (14.3%)
Unknown1 (7.1%)

Top CVEs

Signals from CVEs in this product scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or SHA1 algorithm as trusted.
Dec 21, 20238.627NONO
Local privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to delete files without having proper permission.
Feb 15, 20247.825NONO
ESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attacker to escalate privileges in the context of NT AUTHORITY\SYS
Feb 9, 20227.825NONO
Local privilege escalation in Windows products of ESET allows user who is logged into the system to exploit repair feature of the installer to run malicious code with higher privil
May 11, 20227.824NONO
ESET Cyber Security 6.7.900.0 for macOS allows a local attacker to execute unauthorized commands as root by abusing an undocumented feature in scheduled tasks.
Oct 14, 20197.824NONO
The ESET Personal Firewall NDIS filter (EpFwNdis.sys) driver in the Firewall Module Build 1183 (20140214) and earlier in ESET Smart Security and ESET Endpoint Security products 5.0
Sep 23, 20146.924NONO
Privilege escalation vulnerability in Windows products of ESET, spol. s r.o. allows attacker to exploit "Repair" and "Uninstall" features what may lead to arbitrary file deletion.
May 10, 20227.123NONO
The esets_daemon service in ESET Endpoint Antivirus for macOS before 6.4.168.0 and Endpoint Security for macOS before 6.4.168.0 does not properly verify X.509 certificates from the
Mar 2, 20175.922NONO
ESET was made aware of a vulnerability in its consumer and business products for macOS that enables a user logged on to the system to stop the ESET daemon, effectively disabling th
Nov 8, 20215.520NONO
ESET Antivirus and Antispyware Module module 1553 through 1560 allows a user with limited access rights to create hard links in some ESET directories and then force the product to
Apr 29, 20207.820NONO

Exploit Exposure

Signals from CVEs in this product scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (14 CVEs).

Media Mentions

Signals from CVEs in this product scope (14 CVEs).

Top CNAs Publishing CVEs For Endpoint Security

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.3.70.115.91.7%00
5.0.222816.91.3%00
5.0.222516.91.3%00
5.0.221416.91.3%00
5.0.212616.91.3%00
5.0.212216.91.3%00
5.0.211316.91.3%00