« Volver al listado

CVE-2023-7043

Estado: ModificadaMedia (5.5)—

Unquoted service path in ESET products allows to

drop a prepared program to a specific location and run on boot with the

NT AUTHORITY\NetworkService permissions.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (6)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-7043",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-7043",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-01-31T15:52:23.258496Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@eset.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.3,
          "attackVector": "LOCAL",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@eset.com",
      "affectedData": [
        {
          "vendor": "ESET, spol. s r.o.",
          "product": "ESET Endpoint Security",
          "versions": [
            {
              "status": "affected",
              "version": "10.1.2046.x",
              "versionType": "custom",
              "lessThanOrEqual": "10.1.2063.x"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "ESET, spol. s r.o.",
          "product": "ESET Endpoint Antivirus",
          "versions": [
            {
              "status": "affected",
              "version": "10.1.2046.x",
              "versionType": "custom",
              "lessThanOrEqual": "10.1.2063.x"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "ESET, spol. s r.o.",
          "product": "ESET NOD32 Antivirus",
          "versions": [
            {
              "status": "affected",
              "version": "16.1.14.0",
              "versionType": "custom",
              "lessThanOrEqual": "16.2.15.0"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "ESET, spol. s r.o.",
          "product": "ESET Internet Security",
          "versions": [
            {
              "status": "affected",
              "version": "16.1.14.0",
              "versionType": "custom",
              "lessThanOrEqual": "16.2.15.0"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "ESET, spol. s r.o.",
          "product": "ESET Smart Security Premium",
          "versions": [
            {
              "status": "affected",
              "version": "16.1.14.0",
              "versionType": "custom",
              "lessThanOrEqual": "16.2.15.0"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "ESET, spol. s r.o.",
          "product": "ESET Mail Security for Microsoft Exchange Server",
          "versions": [
            {
              "status": "affected",
              "version": "10.1.10012.0"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-01-31T13:15:10.147",
  "references": [
    {
      "url": "https://support.eset.com/en/ca8602",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@eset.com"
    },
    {
      "url": "https://support.eset.com/en/ca8602",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@eset.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-428"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-428"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Unquoted service path in ESET products allows to \n\ndrop a prepared program to a specific location and run on boot with the \n\nNT AUTHORITY\\NetworkService permissions."
    },
    {
      "lang": "es",
      "value": "La ruta de servicio sin comillas en los productos ESET permite colocar un programa preparado en una ubicación específica y ejecutarlo al arrancar con los permisos NT AUTHORITY\\NetworkService."
    }
  ],
  "lastModified": "2026-06-17T06:51:56.527",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:eset:endpoint_antivirus:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "50677A92-50F3-4020-BC55-B3C6FDB4511D",
              "versionEndExcluding": "11.0.2032.0",
              "versionStartIncluding": "10.1.2046.0"
            },
            {
              "criteria": "cpe:2.3:a:eset:endpoint_security:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "74708E09-04BF-47C1-88A9-B2A0C0FCF3B7",
              "versionEndExcluding": "11.0.2032.0",
              "versionStartIncluding": "10.1.2046.0"
            },
            {
              "criteria": "cpe:2.3:a:eset:internet_security:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "84EF91DD-15F6-4EF8-8B5F-C4CF4DBCBDF9",
              "versionEndExcluding": "17.0.15.0",
              "versionStartIncluding": "16.1.14.0"
            },
            {
              "criteria": "cpe:2.3:a:eset:mail_security:10.1.10012.0:*:*:*:*:exchange_server:*:*",
              "vulnerable": true,
              "matchCriteriaId": "18A15279-74DB-487D-A585-BB07482505E8"
            },
            {
              "criteria": "cpe:2.3:a:eset:nod32_antivirus:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D18A8A98-430B-495B-AAD9-8198E995F77E",
              "versionEndExcluding": "17.0.15.0",
              "versionStartIncluding": "16.1.14.0"
            },
            {
              "criteria": "cpe:2.3:a:eset:smart_security_premium:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "555830F1-6B12-44F7-B912-9061E0EB6E46",
              "versionEndExcluding": "17.0.15.0",
              "versionStartIncluding": "16.1.14.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@eset.com"
}