vendor:
ESET NOD32 Antivirus
by:
Milad Karimi (Ex3ptionaL)
6.1
CVSS
HIGH
Unquoted Service Path
428
CWE
Product Name: ESET NOD32 Antivirus
Affected Version From: 17.0.16.0
Affected Version To: 17.0.16.0
Patch Exists: NO
Related CWE: CVE-2024-XXXXX
CPE: a:eset:nod32_antivirus:17.0.16.0
Platforms Tested: Windows
2024
ESET NOD32 Antivirus 17.0.16.0 – Unquoted Service Path
The ESET NOD32 Antivirus version 17.0.16.0 on Windows 10 has an unquoted service path vulnerability. An attacker could exploit this by placing a malicious executable in a directory included in the system's PATH environment variable, leading to arbitrary code execution. This vulnerability has been identified as CVE-2024-XXXXX.
Mitigation:
To mitigate this vulnerability, ensure that all service paths are quoted properly with the full path to the executable. Regularly monitor and restrict write access to directories containing services.