CVE-2018-0649

HIGH

ESET Internet Security - Untrusted Search Path

Title source: llm
STIX 2.1

Description

Untrusted search path vulnerability in the installers of multiple Canon IT Solutions Inc. software programs (ESET Smart Security Premium, ESET Internet Security, ESET Smart Security, ESET NOD32 Antivirus, DESlock+ Pro, and CompuSec (all programs except packaged ones)) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry third-party-advisory x_refsource_jvn
http://jvn.jp/en/jp/JVN41452671/index.html
Mitigation, Vendor Advisory x_refsource_confirm
https://eset-support.canon-its.jp/faq/show/10720?site_domain=default

Scores

CVSS v3 7.8
EPSS 0.0113
EPSS Percentile 62.2%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-426
Status published
Products (6)
eset/compusec
eset/deslock\+_pro
eset/internet_security
eset/nod32_antivirus
eset/smart_security
eset/smart_security_premium
Published Sep 07, 2018
Tracked Since Feb 18, 2026