« Volver al listado

CVE-2020-11446

Estado: ModificadaAlta (7.8)—

ESET Antivirus and Antispyware Module module 1553 through 1560 allows a user with limited access rights to create hard links in some ESET directories and then force the product to write through these links into files that would normally not be write-able by the user, thus achieving privilege escalation.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (8)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-11446",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.6,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-04-29T14:15:17.607",
  "references": [
    {
      "url": "https://support.eset.com/en/ca7489-local-privilege-escalation-vulnerability-fixed-in-eset-products-for-windows",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://support.eset.com/en/ca7489-local-privilege-escalation-vulnerability-fixed-in-eset-products-for-windows",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-59"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "ESET Antivirus and Antispyware Module module 1553 through 1560 allows a user with limited access rights to create hard links in some ESET directories and then force the product to write through these links into files that would normally not be write-able by the user, thus achieving privilege escalation."
    },
    {
      "lang": "es",
      "value": "Los módulos 1553 hasta 1560 de ESET Antivirus y Antispyware Module, permite a un usuario con derechos de acceso limitados crear enlaces físicos en algunos directorios de ESET y luego forzar al producto a escribir por medio de estos enlaces en archivos que normalmente no podrían ser escritos por el usuario, logrando así una escalada de privilegios."
    }
  ],
  "lastModified": "2026-06-17T02:50:11.587",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:eset:antivirus_and_antispyware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CBC3B9B3-1446-4630-88FE-65D41B1D077D",
              "versionEndIncluding": "1560",
              "versionStartIncluding": "1553"
            },
            {
              "criteria": "cpe:2.3:a:eset:endpoint_antivirus:-:*:*:*:*:-:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2B76C798-A8F7-4705-B85A-98CE4C44AC53"
            },
            {
              "criteria": "cpe:2.3:a:eset:endpoint_security:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "81593DEE-54D7-49D5-9AE6-20B7E2B0AF8F"
            },
            {
              "criteria": "cpe:2.3:a:eset:file_security:-:*:*:*:*:windows_server:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EDA61743-424D-40C9-ADD5-25AF8786BB0E"
            },
            {
              "criteria": "cpe:2.3:a:eset:internet_security:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F2CAD248-1F32-4459-A530-8706E334C67F"
            },
            {
              "criteria": "cpe:2.3:a:eset:mail_security:-:*:*:*:*:domino:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5043B5B1-38B2-4621-B738-A79E5DF8D98E"
            },
            {
              "criteria": "cpe:2.3:a:eset:mail_security:-:*:*:*:*:exchange_server:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DE40A56E-EBC0-43C8-85FB-868802B4817F"
            },
            {
              "criteria": "cpe:2.3:a:eset:mail_security:-:*:*:*:*:kerio:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B322B8F3-DD12-4177-9DDF-BCFCD39DB12A"
            },
            {
              "criteria": "cpe:2.3:a:eset:mail_security:-:*:*:*:*:sharepoint_server:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EB4668BB-DE5D-443B-9A76-353688EE919B"
            },
            {
              "criteria": "cpe:2.3:a:eset:nod32_antivirus:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6253FAFB-0AE6-494A-950D-EB0EB15E982C"
            },
            {
              "criteria": "cpe:2.3:a:eset:nod32_antivirus:-:*:*:*:business:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "12E15271-D518-48E1-AE47-3080A748E131"
            },
            {
              "criteria": "cpe:2.3:a:eset:smart_security:-:*:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CE29DD0C-648B-4B6F-B080-B350E8210B4D"
            },
            {
              "criteria": "cpe:2.3:a:eset:smart_security:-:*:*:*:business:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "38FD5027-F4B6-4398-B93A-DDF0FFC74386"
            },
            {
              "criteria": "cpe:2.3:a:eset:smart_security:-:*:*:*:premium:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "375F46B4-9FDF-48FB-935A-8BB6FEF5221A"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}