CVE-2022-27167
Arbitrary File Deletion in ESET products for Windows
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Privilege escalation vulnerability in Windows products of ESET, spol. s r.o. allows attacker to exploit "Repair" and "Uninstall" features what may lead to arbitrary file deletion. This issue affects: ESET, spol. s r.o. ESET NOD32 Antivirus 11.2 versions prior to 15.1.12.0. ESET, spol. s r.o. ESET Internet Security 11.2 versions prior to 15.1.12.0. ESET, spol. s r.o. ESET Smart Security Premium 11.2 versions prior to 15.1.12.0. ESET, spol. s r.o. ESET Endpoint Antivirus 6.0 versions prior to 9.0.2046.0. ESET, spol. s r.o. ESET Endpoint Security 6.0 versions prior to 9.0.2046.0. ESET, spol. s r.o. ESET Server Security for Microsoft Windows Server 8.0 versions prior to 9.0.12012.0. ESET, spol. s r.o. ESET File Security for Microsoft Windows Server 8.0.12013.0. ESET, spol. s r.o. ESET Mail Security for Microsoft Exchange Server 6.0 versions prior to 8.0.10020.0. ESET, spol. s r.o. ESET Mail Security for IBM Domino 6.0 versions prior to 8.0.14011.0. ESET, spol. s r.o. ESET Security for Microsoft SharePoint Server 6.0 versions prior to 8.0.15009.0.
Una vulnerabilidad de escalada de privilegios en los productos Windows de ESET, spol. s r.o. permite a un atacante explotar las funciones "Repair" y "Uninstall", lo que puede conllevar a una eliminaciĆ³n arbitraria de archivos. Este problema afecta a: ESET, spol. s r.o. ESET NOD32 Antivirus 11.2 versiones anteriores a 15.1.12.0. ESET, spol. s r.o. ESET Internet Security 11.2 versiones anteriores a 15.1.12.0. ESET, spol. s r.o. ESET Smart Security Premium 11.2 versiones anteriores a 15.1.12.0. ESET, spol. s r.o. ESET Endpoint Antivirus 6.0 versiones anteriores a 9.0.2046.0. ESET, spol. s r.o. ESET Endpoint Security 6.0 versiones anteriores a 9.0.2046.0. ESET, spol. s r.o. ESET Server Security for Microsoft Windows Server 8.0 versiones anteriores a 9.0.12012.0. ESET, spol. s r.o. ESET File Security para Microsoft Windows Server 8.0.12013.0. ESET, spol. s r.o. ESET Mail Security para Microsoft Exchange Server 6.0 versiones anteriores a 8.0.10020.0. ESET, spol. s r.o. ESET Mail Security para IBM Domino 6.0 versiones anteriores a 8.0.14011.0. ESET, spol. s r.o. ESET Security para Microsoft SharePoint Server 6.0 versiones anteriores a 8.0.15009.0
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-03-14 CVE Reserved
- 2022-05-10 CVE Published
- 2023-12-01 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-280: Improper Handling of Insufficient Permissions or Privileges
- CWE-755: Improper Handling of Exceptional Conditions
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Eset Search vendor "Eset" | Endpoint Antivirus Search vendor "Eset" for product "Endpoint Antivirus" | >= 6.0 < 8.0.2053.0 Search vendor "Eset" for product "Endpoint Antivirus" and version " >= 6.0 < 8.0.2053.0" | windows |
Affected
| ||||||
Eset Search vendor "Eset" | Endpoint Antivirus Search vendor "Eset" for product "Endpoint Antivirus" | >= 8.1 < 8.1.2050.0 Search vendor "Eset" for product "Endpoint Antivirus" and version " >= 8.1 < 8.1.2050.0" | windows |
Affected
| ||||||
Eset Search vendor "Eset" | Endpoint Antivirus Search vendor "Eset" for product "Endpoint Antivirus" | >= 9.0 < 9.0.2046.0 Search vendor "Eset" for product "Endpoint Antivirus" and version " >= 9.0 < 9.0.2046.0" | windows |
Affected
| ||||||
Eset Search vendor "Eset" | Endpoint Security Search vendor "Eset" for product "Endpoint Security" | >= 6.0 < 8.0.2053.0 Search vendor "Eset" for product "Endpoint Security" and version " >= 6.0 < 8.0.2053.0" | windows |
Affected
| ||||||
Eset Search vendor "Eset" | Endpoint Security Search vendor "Eset" for product "Endpoint Security" | >= 8.1 < 8.1.2050.0 Search vendor "Eset" for product "Endpoint Security" and version " >= 8.1 < 8.1.2050.0" | windows |
Affected
| ||||||
Eset Search vendor "Eset" | Endpoint Security Search vendor "Eset" for product "Endpoint Security" | >= 9.0 < 9.0.2046.0 Search vendor "Eset" for product "Endpoint Security" and version " >= 9.0 < 9.0.2046.0" | windows |
Affected
| ||||||
Eset Search vendor "Eset" | File Security Search vendor "Eset" for product "File Security" | >= 6.0 < 8.0.12013.0 Search vendor "Eset" for product "File Security" and version " >= 6.0 < 8.0.12013.0" | windows_server |
Affected
| ||||||
Eset Search vendor "Eset" | Internet Security Search vendor "Eset" for product "Internet Security" | >= 11.2 < 15.1.12.0 Search vendor "Eset" for product "Internet Security" and version " >= 11.2 < 15.1.12.0" | windows |
Affected
| ||||||
Eset Search vendor "Eset" | Mail Security Search vendor "Eset" for product "Mail Security" | >= 6.0 < 8.0.10020.0 Search vendor "Eset" for product "Mail Security" and version " >= 6.0 < 8.0.10020.0" | exchange_server |
Affected
| ||||||
Eset Search vendor "Eset" | Mail Security Search vendor "Eset" for product "Mail Security" | >= 6.0 < 8.0.14011.0 Search vendor "Eset" for product "Mail Security" and version " >= 6.0 < 8.0.14011.0" | domino |
Affected
| ||||||
Eset Search vendor "Eset" | Nod32 Antivirus Search vendor "Eset" for product "Nod32 Antivirus" | >= 11.2 < 15.1.12.0 Search vendor "Eset" for product "Nod32 Antivirus" and version " >= 11.2 < 15.1.12.0" | windows |
Affected
| ||||||
Eset Search vendor "Eset" | Security Search vendor "Eset" for product "Security" | >= 6.0 < 8.0.15009.0 Search vendor "Eset" for product "Security" and version " >= 6.0 < 8.0.15009.0" | sharepoint_server |
Affected
| ||||||
Eset Search vendor "Eset" | Server Security Search vendor "Eset" for product "Server Security" | >= 6.0 Search vendor "Eset" for product "Server Security" and version " >= 6.0" | azure |
Affected
| ||||||
Eset Search vendor "Eset" | Server Security Search vendor "Eset" for product "Server Security" | >= 8.0 < 9.0.12012.0 Search vendor "Eset" for product "Server Security" and version " >= 8.0 < 9.0.12012.0" | windows_server |
Affected
| ||||||
Eset Search vendor "Eset" | Smart Security Search vendor "Eset" for product "Smart Security" | >= 11.2 < 15.1.12.0 Search vendor "Eset" for product "Smart Security" and version " >= 11.2 < 15.1.12.0" | premium, windows |
Affected
|