Threat Advisory

ESET Patches High-Severity Privilege Escalation Vulnerability

Threat: Vulnerability
Threat Actor Type: NA
Targeted Region: NA
Threat Actor Region: NA
Targeted Sector: NA
Criticality: High
[subscribe_to_unlock_form]

Summary:

Cybersecurity firm ESET has issued a critical security advisory for its consumer, business, and server security products on Windows, addressing a high-severity vulnerability. Tracked as CVE-2024-0353 with a CVSS score of 7.8, the flaw is found in the real-time file system protection component, which handles file operations. The vulnerability, if exploited, could lead to an elevation of privilege, allowing an attacker with low privileges to delete arbitrary files with System privileges. This issue was flagged by researchers . While ESET has confirmed no evidence of in-the-wild exploitation, the company has released patches for various products, including antivirus, endpoint, and server products for Windows, as well as email security and products for Exchange Server, IBM Domino, SharePoint Server, and Azure. It is advised that ESET customers, excluding those with products that have reached end-of-life status, apply these patches promptly to mitigate potential risks.[/subscribe_to_unlock_form]

Summary:

Cybersecurity firm ESET has issued a critical security advisory for its consumer, business, and server security products on Windows, addressing a high-severity vulnerability. Tracked as CVE-2024-0353 with a CVSS score of 7.8, the flaw is found in the real-time file system protection component, which handles file operations. The vulnerability, if exploited, could lead to an elevation of privilege, allowing an attacker with low privileges to delete arbitrary files with System privileges. This issue was flagged by researchers . While ESET has confirmed no evidence of in-the-wild exploitation, the company has released patches for various products, including antivirus, endpoint, and server products for Windows, as well as email security and products for Exchange Server, IBM Domino, SharePoint Server, and Azure. It is advised that ESET customers, excluding those with products that have reached end-of-life status, apply these patches promptly to mitigate potential risks.[emaillocker id="1283"]

Recommendations:

We strongly recommend you update ESET security products to below versions :

  • ESET NOD32 Antivirus, ESET Internet Security, ESET Smart Security Premium, ESET Security Ultimate 17.0.10.0 and later
  • ESET Endpoint Antivirus for Windows and ESET Endpoint Security for Windows 11.0.2032.0, 10.1.2063.0, 10.0.2052.0, 9.1.2071.0, 8.1.2062.0 and later from the respective version family
  • ESET Server Security for Windows Server (formerly File Security for Microsoft Windows Server) 10.0.12015.0, 9.0.12019.0, 8.0.12016.0, 7.3.12013.0 and later from the respective version family
  • ESET Mail Security for Microsoft Exchange Server 10.1.10014.0, 10.0.10018.0, 9.0.10012.0, 8.0.10024.0, 7.3.10018.0 and later from the respective version family
  • ESET Mail Security for IBM Domino 10.0.14007.0, 9.0.14008.0, 8.0.14014.0, 7.3.14006.0 and later from the respective version family
  • ESET Security for Microsoft SharePoint Server 10.0.15005.0, 9.0.15006.0, 8.0.15012.0, 7.3.15006.0 and later from the respective version family
  • ESET File Security for Microsoft Azure customers should migrate to the latest version of ESET Server Security for Microsoft Windows Server

References:

The following reports contain further technical details:

https://www.securityweek.com/eset-patches-high-severity-privilege-escalation-vulnerability/

[/emaillocker]
crossmenu