CVE-2018-0649

Untrusted search path vulnerability in the installers of multiple Canon IT Solutions Inc. software programs (ESET Smart Security Premium, ESET Internet Security, ESET Smart Security, ESET NOD32 Antivirus, DESlock+ Pro, and CompuSec (all programs except packaged ones)) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:eset:compusec:-:*:*:*:*:*:*:*
cpe:2.3:a:eset:deslock\+_pro:-:*:*:*:*:*:*:*
cpe:2.3:a:eset:internet_security:-:*:*:*:*:*:*:*
cpe:2.3:a:eset:nod32_antivirus:-:*:*:*:*:*:*:*
cpe:2.3:a:eset:smart_security:-:*:*:*:*:*:*:*
cpe:2.3:a:eset:smart_security_premium:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:38

Type Values Removed Values Added
References () http://jvn.jp/en/jp/JVN41452671/index.html - Third Party Advisory, VDB Entry () http://jvn.jp/en/jp/JVN41452671/index.html - Third Party Advisory, VDB Entry
References () https://eset-support.canon-its.jp/faq/show/10720?site_domain=default - Mitigation, Vendor Advisory () https://eset-support.canon-its.jp/faq/show/10720?site_domain=default - Mitigation, Vendor Advisory

Information

Published : 2018-09-07 14:29

Updated : 2024-11-21 03:38


NVD link : CVE-2018-0649

Mitre link : CVE-2018-0649

CVE.ORG link : CVE-2018-0649


JSON object : View

Products Affected

eset

  • internet_security
  • smart_security_premium
  • smart_security
  • compusec
  • nod32_antivirus
  • deslock\+_pro
CWE
CWE-426

Untrusted Search Path