CVE-2023-3160

HIGH

ESET Endpoint Antivirus - Improper Privilege Management via Module Update File Operations

Title source: llm
STIX 2.1

Description

The vulnerability potentially allows an attacker to misuse ESET’s file operations during the module update to delete or move files without having proper permissions.

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0018
EPSS Percentile 7.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (8)
eset/endpoint_antivirus
eset/endpoint_security
eset/internet_security
eset/mail_security (2 CPE variants)
eset/nod32
eset/security
eset/server_security
eset/smart_security
Published Aug 14, 2023
Tracked Since Feb 18, 2026