// For flags

CVE-2021-37850

Denial of service in ESET for Mac products

Severity Score

5.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

ESET was made aware of a vulnerability in its consumer and business products for macOS that enables a user logged on to the system to stop the ESET daemon, effectively disabling the protection of the ESET security product until a system reboot.

ESET se dio cuenta de una vulnerabilidad en sus productos de consumo y empresariales para macOS que permite a un usuario conectado al sistema detener el demonio de ESET, deshabilitando efectivamente la protección del producto de seguridad de ESET hasta un reinicio del sistema

*Credits: ESET values the principles of responsible disclosure within the security industry and would like to express our thanks to Teiei Shu (廷叡 周) who reported this issue.
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-08-02 CVE Reserved
  • 2021-11-08 CVE Published
  • 2023-06-01 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
References (1)
URL Tag Source
URL Date SRC
URL Date SRC
URL Date SRC
https://support.eset.com/en/ca8151 2021-11-09
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Eset
Search vendor "Eset"
Cyber Security
Search vendor "Eset" for product "Cyber Security"
<= 6.10.700
Search vendor "Eset" for product "Cyber Security" and version " <= 6.10.700"
macos
Affected
Eset
Search vendor "Eset"
Cyber Security
Search vendor "Eset" for product "Cyber Security"
<= 6.10.700
Search vendor "Eset" for product "Cyber Security" and version " <= 6.10.700"
pro, macos
Affected
Eset
Search vendor "Eset"
Endpoint Antivirus
Search vendor "Eset" for product "Endpoint Antivirus"
<= 6.10.910.0
Search vendor "Eset" for product "Endpoint Antivirus" and version " <= 6.10.910.0"
macos
Affected
Eset
Search vendor "Eset"
Endpoint Security
Search vendor "Eset" for product "Endpoint Security"
<= 6.10.910.0
Search vendor "Eset" for product "Endpoint Security" and version " <= 6.10.910.0"
macos
Affected