CVE-2020-11446
Estado: ModificadaAlta (7.8)—
ESET Antivirus and Antispyware Module module 1553 through 1560 allows a user with limited access rights to create hard links in some ESET directories and then force the product to write through these links into files that would normally not be write-able by the user, thus achieving privilege escalation.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.38%
- Percentil entre todas las CVEs puntuadas: 30
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (8)
CWE
- CWE-59
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-11446",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.6,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2020-04-29T14:15:17.607",
"references": [
{
"url": "https://support.eset.com/en/ca7489-local-privilege-escalation-vulnerability-fixed-in-eset-products-for-windows",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://support.eset.com/en/ca7489-local-privilege-escalation-vulnerability-fixed-in-eset-products-for-windows",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-59"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "ESET Antivirus and Antispyware Module module 1553 through 1560 allows a user with limited access rights to create hard links in some ESET directories and then force the product to write through these links into files that would normally not be write-able by the user, thus achieving privilege escalation."
},
{
"lang": "es",
"value": "Los módulos 1553 hasta 1560 de ESET Antivirus y Antispyware Module, permite a un usuario con derechos de acceso limitados crear enlaces físicos en algunos directorios de ESET y luego forzar al producto a escribir por medio de estos enlaces en archivos que normalmente no podrían ser escritos por el usuario, logrando así una escalada de privilegios."
}
],
"lastModified": "2026-06-17T02:50:11.587",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:eset:antivirus_and_antispyware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CBC3B9B3-1446-4630-88FE-65D41B1D077D",
"versionEndIncluding": "1560",
"versionStartIncluding": "1553"
},
{
"criteria": "cpe:2.3:a:eset:endpoint_antivirus:-:*:*:*:*:-:*:*",
"vulnerable": true,
"matchCriteriaId": "2B76C798-A8F7-4705-B85A-98CE4C44AC53"
},
{
"criteria": "cpe:2.3:a:eset:endpoint_security:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "81593DEE-54D7-49D5-9AE6-20B7E2B0AF8F"
},
{
"criteria": "cpe:2.3:a:eset:file_security:-:*:*:*:*:windows_server:*:*",
"vulnerable": true,
"matchCriteriaId": "EDA61743-424D-40C9-ADD5-25AF8786BB0E"
},
{
"criteria": "cpe:2.3:a:eset:internet_security:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F2CAD248-1F32-4459-A530-8706E334C67F"
},
{
"criteria": "cpe:2.3:a:eset:mail_security:-:*:*:*:*:domino:*:*",
"vulnerable": true,
"matchCriteriaId": "5043B5B1-38B2-4621-B738-A79E5DF8D98E"
},
{
"criteria": "cpe:2.3:a:eset:mail_security:-:*:*:*:*:exchange_server:*:*",
"vulnerable": true,
"matchCriteriaId": "DE40A56E-EBC0-43C8-85FB-868802B4817F"
},
{
"criteria": "cpe:2.3:a:eset:mail_security:-:*:*:*:*:kerio:*:*",
"vulnerable": true,
"matchCriteriaId": "B322B8F3-DD12-4177-9DDF-BCFCD39DB12A"
},
{
"criteria": "cpe:2.3:a:eset:mail_security:-:*:*:*:*:sharepoint_server:*:*",
"vulnerable": true,
"matchCriteriaId": "EB4668BB-DE5D-443B-9A76-353688EE919B"
},
{
"criteria": "cpe:2.3:a:eset:nod32_antivirus:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6253FAFB-0AE6-494A-950D-EB0EB15E982C"
},
{
"criteria": "cpe:2.3:a:eset:nod32_antivirus:-:*:*:*:business:*:*:*",
"vulnerable": true,
"matchCriteriaId": "12E15271-D518-48E1-AE47-3080A748E131"
},
{
"criteria": "cpe:2.3:a:eset:smart_security:-:*:*:*:-:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CE29DD0C-648B-4B6F-B080-B350E8210B4D"
},
{
"criteria": "cpe:2.3:a:eset:smart_security:-:*:*:*:business:*:*:*",
"vulnerable": true,
"matchCriteriaId": "38FD5027-F4B6-4398-B93A-DDF0FFC74386"
},
{
"criteria": "cpe:2.3:a:eset:smart_security:-:*:*:*:premium:*:*:*",
"vulnerable": true,
"matchCriteriaId": "375F46B4-9FDF-48FB-935A-8BB6FEF5221A"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}