CVE-2023-7043

CWE-4283 documents3 sources
Severity
5.5MEDIUM
EPSS
0.1%
top 81.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 31

Description

Unquoted service path in ESET products allows to drop a prepared program to a specific location and run on boot with the NT AUTHORITY\NetworkService permissions.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages12 packages

NVDeset/nod32_antivirus16.1.14.017.0.15.0
NVDeset/endpoint_security10.1.2046.011.0.2032.0
NVDeset/internet_security16.1.14.017.0.15.0
NVDeset/endpoint_antivirus10.1.2046.011.0.2032.0
NVDeset/smart_security_premium16.1.14.017.0.15.0

🔴Vulnerability Details

2
CVEList
Unquoted path privilege vulnerability in ESET products for Windows2024-01-31
GHSA
GHSA-m5qf-4xvf-462h: Unquoted service path in ESET products allows to drop a prepared program to a specific location and run on boot with the NT AUTHORITY\NetworkService2024-01-31
CVE-2023-7043 (MEDIUM CVSS 5.5) | Unquoted service path in ESET produ | cvebase.io