Refine your search

2 vulnerabilities found for by ESET, spol. s.r.o.

CVE-2026-6424 (GCVE-0-2026-6424)
Vulnerability from cvelistv5
Published
2026-07-16 08:28
Modified
2026-07-16 12:17
CWE
Summary
Use-after-free vulnerability in ESET Linux products potentially allowed an attacker to trigger kernel panic on the system
Impacted products
Vendor Product Version
ESET, spol. s.r.o. ESET Endpoint Antivirus for Linux Version: 13.1   <
Version: 13.0   <
Version: 12.2   <
Version: 12.1   <
Version: 12.0   <
Create a notification for this product.
   ESET, spol. s.r.o. ESET Server Security for Linux Version: 13.1   <
Version: 13.0   <
Version: 12.2   <
Version: 12.1   <
Version: 12.0   <
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-6424",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-07-16T12:17:24.495540Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-07-16T12:17:48.734Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "platforms": [
            "Linux"
          ],
          "product": "ESET Endpoint Antivirus for Linux",
          "vendor": "ESET, spol. s.r.o.",
          "versions": [
            {
              "changes": [
                {
                  "at": "13.1.5.0",
                  "status": "unaffected"
                }
              ],
              "lessThanOrEqual": "13.1.3.0",
              "status": "affected",
              "version": "13.1",
              "versionType": "custom"
            },
            {
              "changes": [
                {
                  "at": "13.0.5.0",
                  "status": "unaffected"
                }
              ],
              "lessThanOrEqual": "13.0.3.0",
              "status": "affected",
              "version": "13.0",
              "versionType": "custom"
            },
            {
              "changes": [
                {
                  "at": "12.2.9.0",
                  "status": "unaffected"
                }
              ],
              "lessThanOrEqual": "12.2.8.0",
              "status": "affected",
              "version": "12.2",
              "versionType": "custom"
            },
            {
              "changes": [
                {
                  "at": "12.1.2.0",
                  "status": "unaffected"
                }
              ],
              "lessThanOrEqual": "12.1.1.0",
              "status": "affected",
              "version": "12.1",
              "versionType": "custom"
            },
            {
              "changes": [
                {
                  "at": "12.0.14.0",
                  "status": "unaffected"
                }
              ],
              "lessThanOrEqual": "12.0.13.0",
              "status": "affected",
              "version": "12.0",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "13.2.3.0"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "platforms": [
            "Linux"
          ],
          "product": "ESET Server Security for Linux",
          "vendor": "ESET, spol. s.r.o.",
          "versions": [
            {
              "changes": [
                {
                  "at": "13.1.118.0",
                  "status": "unaffected"
                }
              ],
              "lessThanOrEqual": "13.1.116.0",
              "status": "affected",
              "version": "13.1",
              "versionType": "custom"
            },
            {
              "changes": [
                {
                  "at": "13.0.36.0",
                  "status": "unaffected"
                }
              ],
              "lessThanOrEqual": "13.0.34.0",
              "status": "affected",
              "version": "13.0",
              "versionType": "custom"
            },
            {
              "changes": [
                {
                  "at": "12.2.73.0",
                  "status": "unaffected"
                }
              ],
              "lessThanOrEqual": "12.2.72.0",
              "status": "affected",
              "version": "12.2",
              "versionType": "custom"
            },
            {
              "changes": [
                {
                  "at": "12.1.407.0",
                  "status": "unaffected"
                }
              ],
              "lessThanOrEqual": "12.1.406.0",
              "status": "affected",
              "version": "12.1",
              "versionType": "custom"
            },
            {
              "changes": [
                {
                  "at": "12.0.292.0",
                  "status": "unaffected"
                }
              ],
              "lessThanOrEqual": "12.0.287.0",
              "status": "affected",
              "version": "12.0",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "13.2.53.0"
            }
          ]
        }
      ],
      "datePublic": "2026-07-16T08:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "Use-after-free vulnerability in ESET Linux products\u0026nbsp;potentially allowed an attacker to trigger kernel panic on the system"
            }
          ],
          "value": "Use-after-free vulnerability in ESET Linux products\u00a0potentially allowed an attacker to trigger kernel panic on the system"
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-129",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-129 Pointer Manipulation"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "LOCAL",
            "baseScore": 6.7,
            "baseSeverity": "MEDIUM",
            "exploitMaturity": "NOT_DEFINED",
            "privilegesRequired": "HIGH",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-416",
              "description": "CWE-416 Use after free",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-07-16T08:28:43.649Z",
        "orgId": "4a9b9929-2450-4021-b7b9-469a0255b215",
        "shortName": "ESET"
      },
      "references": [
        {
          "url": "https://support.eset.com/en/ca8972-eset-customer-advisory-use-after-free-vulnerability-in-eset-security-products-for-linux-fixed"
        }
      ],
      "source": {
        "advisory": "CA8972",
        "discovery": "UNKNOWN"
      },
      "title": "Use-after-free vulnerability in ESET security products for Linux",
      "x_generator": {
        "engine": "Vulnogram 1.0.2"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "4a9b9929-2450-4021-b7b9-469a0255b215",
    "assignerShortName": "ESET",
    "cveId": "CVE-2026-6424",
    "datePublished": "2026-07-16T08:28:43.649Z",
    "dateReserved": "2026-04-16T08:13:25.859Z",
    "dateUpdated": "2026-07-16T12:17:48.734Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-6423 (GCVE-0-2026-6423)
Vulnerability from cvelistv5
Published
2026-07-16 07:56
Modified
2026-07-16 12:34
CWE
  • CWE-269 - Improper Privilege Management
Summary
A local privilege escalation vulnerability in ESET Inspect Connector.  The vulnerability was caused by improper authentication in an IPC channel.
Impacted products
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-6423",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-07-16T12:34:20.351046Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-07-16T12:34:49.159Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "platforms": [
            "Windows"
          ],
          "product": "ESET Inspect Connector",
          "vendor": "ESET, spol. s.r.o.",
          "versions": [
            {
              "lessThanOrEqual": "3.0.5775.0",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        }
      ],
      "datePublic": "2026-07-16T08:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "A local privilege escalation vulnerability in ESET Inspect Connector.\u0026nbsp;\nThe vulnerability was caused by improper authentication in an IPC channel."
            }
          ],
          "value": "A local privilege escalation vulnerability in ESET Inspect Connector.\u00a0\nThe vulnerability was caused by improper authentication in an IPC channel."
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-233",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-233 Privilege Escalation"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "LOCAL",
            "baseScore": 8.5,
            "baseSeverity": "HIGH",
            "exploitMaturity": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "HIGH",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-269",
              "description": "CWE-269 Improper Privilege Management",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-07-16T07:56:20.026Z",
        "orgId": "4a9b9929-2450-4021-b7b9-469a0255b215",
        "shortName": "ESET"
      },
      "references": [
        {
          "url": "https://support.eset.com/en/ca8970-eset-customer-advisory-local-privilege-escalation-via-unauthenticated-alpc-in-eset-inspect-connector-for-windows-fixed"
        }
      ],
      "source": {
        "advisory": "CA8970",
        "discovery": "UNKNOWN"
      },
      "title": "Local privilege escalation via unauthenticated ALPC in ESET Inspect Connector",
      "x_generator": {
        "engine": "Vulnogram 1.0.2"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "4a9b9929-2450-4021-b7b9-469a0255b215",
    "assignerShortName": "ESET",
    "cveId": "CVE-2026-6423",
    "datePublished": "2026-07-16T07:56:20.026Z",
    "dateReserved": "2026-04-16T08:03:11.185Z",
    "dateUpdated": "2026-07-16T12:34:49.159Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}