CVE-2024-7400Insecure Operation on Windows Junction / Mount Point in Spol S R.O Eset Endpoint Antivirus

Severity
8.5HIGHNVD
EPSS
0.1%
top 69.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 27
Latest updateJan 8

Description

The vulnerability potentially allowed an attacker to misuse ESET’s file operations during the removal of a detected file on the Windows operating system to delete files without having proper permissions to do so.

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

🔴Vulnerability Details

3
OSV
powerpc/prom_init: Fixup missing powermac #size-cells2025-01-08
CVEList
Local privilege escalation in ESET products for Windows2024-09-27
GHSA
GHSA-3f69-f27h-f53w: The vulnerability potentially allowed an attacker to misuse ESET’s file operations during the removal of a detected file on the Windows operating syst2024-09-27
CVE-2024-7400 — HIGH severity | cvebase