// For flags

CVE-2022-2402

Stack Overflow in ESET Endpoint Encryption and ESET Full Disk Encryption for Windows

Severity Score

6.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The vulnerability in the driver dlpfde.sys enables a user logged into the system to perform system calls leading to kernel stack overflow, resulting in a system crash, for instance, a BSOD.

Una vulnerabilidad en el controlador dlpfde.sys permite a un usuario que haya iniciado sesiĆ³n en el sistema llevar a cabo llamadas al sistema, conllevando a un desbordamiento de la pila del kernel, resultando en un bloqueo del sistema, por ejemplo, un BSOD.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
None
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-07-14 CVE Reserved
  • 2022-09-06 CVE Published
  • 2024-09-16 CVE Updated
  • 2024-10-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-121: Stack-based Buffer Overflow
  • CWE-787: Out-of-bounds Write
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Eset
Search vendor "Eset"
Endpoint Encryption
Search vendor "Eset" for product "Endpoint Encryption"
< 5.1.2.26
Search vendor "Eset" for product "Endpoint Encryption" and version " < 5.1.2.26"
-
Affected
Eset
Search vendor "Eset"
Full Disk Encryption
Search vendor "Eset" for product "Full Disk Encryption"
< 1.3.2.32
Search vendor "Eset" for product "Full Disk Encryption" and version " < 1.3.2.32"
-
Affected