CVE-2024-11859Uncontrolled Search Path Element in Spol S R.O Eset Endpoint Antivirus FOR Windows

Severity
8.4HIGHNVD
EPSS
0.4%
top 42.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 7

Description

DLL Search Order Hijacking vulnerability potentially allowed an attacker with administrator privileges to load a malicious dynamic-link library and execute its code.

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Packages11 packages

🔴Vulnerability Details

3
CVEList
DLL Search Order Hijacking in ESET products for Windows2025-04-07
GHSA
GHSA-w85p-m37q-fvfw: DLL Search Order Hijacking vulnerability potentially allowed an attacker with administrator privileges to load a malicious dynamic-link library and ex2025-04-07
VulnCheck
eset internet_security Uncontrolled Search Path Element2024

🕵️Threat Intelligence

1
Securelist
How ToddyCat tried to hide behind AV software2025-04-07
CVE-2024-11859 — Uncontrolled Search Path Element | cvebase