// For flags

CVE-2022-2402

Stack Overflow in ESET Endpoint Encryption and ESET Full Disk Encryption for Windows

Severity Score

6.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The vulnerability in the driver dlpfde.sys enables a user logged into the system to perform system calls leading to kernel stack overflow, resulting in a system crash, for instance, a BSOD.

Una vulnerabilidad en el controlador dlpfde.sys permite a un usuario que haya iniciado sesiĆ³n en el sistema llevar a cabo llamadas al sistema, conllevando a un desbordamiento de la pila del kernel, resultando en un bloqueo del sistema, por ejemplo, un BSOD.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Local
Attack Complexity
Low
Authentication
Single
Confidentiality
None
Integrity
None
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-07-14 CVE Reserved
  • 2022-09-06 CVE Published
  • 2024-09-16 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-121: Stack-based Buffer Overflow
  • CWE-787: Out-of-bounds Write
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Eset
Search vendor "Eset"
Endpoint Encryption
Search vendor "Eset" for product "Endpoint Encryption"
< 5.1.2.26
Search vendor "Eset" for product "Endpoint Encryption" and version " < 5.1.2.26"
-
Affected
Eset
Search vendor "Eset"
Full Disk Encryption
Search vendor "Eset" for product "Full Disk Encryption"
< 1.3.2.32
Search vendor "Eset" for product "Full Disk Encryption" and version " < 1.3.2.32"
-
Affected