HIGH · 7.8

CVE-2020-11446

ESET Antivirus and Antispyware Module module 1553 through 1560 allows a user with limited access rights to create hard links in some ESET directories and then force the product to write through these ...

Vulnerability Description

ESET Antivirus and Antispyware Module module 1553 through 1560 allows a user with limited access rights to create hard links in some ESET directories and then force the product to write through these links into files that would normally not be write-able by the user, thus achieving privilege escalation.

CVSS Score

7.8

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
EsetAntivirus And Antispyware>= 1553, <= 1560
EsetEndpoint Antivirus-
EsetEndpoint Security-
EsetFile Security-
EsetInternet Security-
EsetMail Security-
EsetNod32 Antivirus-
EsetSmart Security-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-11446?

CVE-2020-11446 is a vulnerability with a CVSS score of 7.8 (HIGH). ESET Antivirus and Antispyware Module module 1553 through 1560 allows a user with limited access rights to create hard links in some ESET directories and then force the product to write through these ...

How severe is CVE-2020-11446?

CVE-2020-11446 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-11446?

Check the references section above for vendor advisories and patch information. Affected products include: Eset Antivirus And Antispyware, Eset Endpoint Antivirus, Eset Endpoint Security, Eset File Security, Eset Internet Security.