Lucene search

K
cve[email protected]CVE-2014-4973
HistorySep 23, 2014 - 3:55 p.m.

CVE-2014-4973

2014-09-2315:55:06
CWE-20
web.nvd.nist.gov
24
eset
personal firewall
ndis filter
epfwndis.sys
firewall module
smart security
endpoint security
cve-2014-4973
nvd

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

6.6 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

The ESET Personal Firewall NDIS filter (EpFwNdis.sys) driver in the Firewall Module Build 1183 (20140214) and earlier in ESET Smart Security and ESET Endpoint Security products 5.0 through 7.0 allows local users to gain privileges via a crafted argument to a 0x830020CC IOCTL call.

Affected configurations

NVD
Node
esetsmart_securityMatch5.0.94
OR
esetsmart_securityMatch5.0.95
OR
esetsmart_securityMatch5.2.9
OR
esetsmart_securityMatch5.2.15
OR
esetsmart_securityMatch6.0.306
OR
esetsmart_securityMatch6.0.308
OR
esetsmart_securityMatch6.0.314
OR
esetsmart_securityMatch6.0.316
Node
esetendpoint_securityMatch5.0.2113
OR
esetendpoint_securityMatch5.0.2122
OR
esetendpoint_securityMatch5.0.2126
OR
esetendpoint_securityMatch5.0.2214
OR
esetendpoint_securityMatch5.0.2225
OR
esetendpoint_securityMatch5.0.2228

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

6.6 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%