CVE-2018-0649
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Untrusted search path vulnerability in the installers of multiple Canon IT Solutions Inc. software programs (ESET Smart Security Premium, ESET Internet Security, ESET Smart Security, ESET NOD32 Antivirus, DESlock+ Pro, and CompuSec (all programs except packaged ones)) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Vulnerabilidad de ruta de búsqueda no fiable en los instaladores de múltiples programas de software de Canon IT Solutions Inc. (ESET Smart Security Premium, ESET Internet Security, ESET Smart Security, ESET NOD32 Antivirus, DESlock+ Pro y CompuSec; todos los programas menos los empaquetados) permite que un atacante obtenga privilegios mediante un archivo DLL troyano en un directorio sin especificar.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-11-27 CVE Reserved
- 2018-09-07 CVE Published
- 2024-01-29 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-426: Untrusted Search Path
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://jvn.jp/en/jp/JVN41452671/index.html | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://eset-support.canon-its.jp/faq/show/10720?site_domain=default | 2018-11-19 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Eset Search vendor "Eset" | Compusec Search vendor "Eset" for product "Compusec" | - | - |
Affected
| ||||||
Eset Search vendor "Eset" | Deslock\+ Pro Search vendor "Eset" for product "Deslock\+ Pro" | - | - |
Affected
| ||||||
Eset Search vendor "Eset" | Internet Security Search vendor "Eset" for product "Internet Security" | - | - |
Affected
| ||||||
Eset Search vendor "Eset" | Nod32 Antivirus Search vendor "Eset" for product "Nod32 Antivirus" | - | - |
Affected
| ||||||
Eset Search vendor "Eset" | Smart Security Search vendor "Eset" for product "Smart Security" | - | - |
Affected
| ||||||
Eset Search vendor "Eset" | Smart Security Premium Search vendor "Eset" for product "Smart Security Premium" | - | - |
Affected
|