MEDIUM · 5.5

CVE-2020-9264

ESET Archive Support Module before 1296 allows virus-detection bypass via a crafted Compression Information Field in a ZIP archive. This affects versions before 1294 of Smart Security Premium, Interne...

Vulnerability Description

ESET Archive Support Module before 1296 allows virus-detection bypass via a crafted Compression Information Field in a ZIP archive. This affects versions before 1294 of Smart Security Premium, Internet Security, NOD32 Antivirus, Cyber Security Pro (macOS), Cyber Security (macOS), Mobile Security for Android, Smart TV Security, and NOD32 Antivirus 4 for Linux Desktop.

CVSS Score

5.5

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
EsetCyber Security< 1296
EsetInternet Security< 1296
EsetMobile Security< 1296
EsetNod32 Antivirus< 1296
EsetSmart Security< 1296
EsetSmart Tv Security< 1296

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-9264?

CVE-2020-9264 is a vulnerability with a CVSS score of 5.5 (MEDIUM). ESET Archive Support Module before 1296 allows virus-detection bypass via a crafted Compression Information Field in a ZIP archive. This affects versions before 1294 of Smart Security Premium, Interne...

How severe is CVE-2020-9264?

CVE-2020-9264 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-9264?

Check the references section above for vendor advisories and patch information. Affected products include: Eset Cyber Security, Eset Internet Security, Eset Mobile Security, Eset Nod32 Antivirus, Eset Smart Security.