CVE-2022-27167
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/05/2022
Last modified:
18/05/2022
Description
Privilege escalation vulnerability in Windows products of ESET, spol. s r.o. allows attacker to exploit "Repair" and "Uninstall" features what may lead to arbitrary file deletion. This issue affects: ESET, spol. s r.o. ESET NOD32 Antivirus 11.2 versions prior to 15.1.12.0. ESET, spol. s r.o. ESET Internet Security 11.2 versions prior to 15.1.12.0. ESET, spol. s r.o. ESET Smart Security Premium 11.2 versions prior to 15.1.12.0. ESET, spol. s r.o. ESET Endpoint Antivirus 6.0 versions prior to 9.0.2046.0. ESET, spol. s r.o. ESET Endpoint Security 6.0 versions prior to 9.0.2046.0. ESET, spol. s r.o. ESET Server Security for Microsoft Windows Server 8.0 versions prior to 9.0.12012.0. ESET, spol. s r.o. ESET File Security for Microsoft Windows Server 8.0.12013.0. ESET, spol. s r.o. ESET Mail Security for Microsoft Exchange Server 6.0 versions prior to 8.0.10020.0. ESET, spol. s r.o. ESET Mail Security for IBM Domino 6.0 versions prior to 8.0.14011.0. ESET, spol. s r.o. ESET Security for Microsoft SharePoint Server 6.0 versions prior to 8.0.15009.0.
Impact
Base Score 3.x
7.10
Severity 3.x
HIGH
Base Score 2.0
3.60
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:eset:endpoint_antivirus:*:*:*:*:*:windows:*:* | 6.0 (including) | 8.0.2053.0 (excluding) |
| cpe:2.3:a:eset:endpoint_antivirus:*:*:*:*:*:windows:*:* | 8.1 (including) | 8.1.2050.0 (excluding) |
| cpe:2.3:a:eset:endpoint_antivirus:*:*:*:*:*:windows:*:* | 9.0 (including) | 9.0.2046.0 (excluding) |
| cpe:2.3:a:eset:endpoint_security:*:*:*:*:*:windows:*:* | 6.0 (including) | 8.0.2053.0 (excluding) |
| cpe:2.3:a:eset:endpoint_security:*:*:*:*:*:windows:*:* | 8.1 (including) | 8.1.2050.0 (excluding) |
| cpe:2.3:a:eset:endpoint_security:*:*:*:*:*:windows:*:* | 9.0 (including) | 9.0.2046.0 (excluding) |
| cpe:2.3:a:eset:file_security:*:*:*:*:*:windows_server:*:* | 6.0 (including) | 8.0.12013.0 (excluding) |
| cpe:2.3:a:eset:internet_security:*:*:*:*:*:windows:*:* | 11.2 (including) | 15.1.12.0 (excluding) |
| cpe:2.3:a:eset:mail_security:*:*:*:*:*:exchange_server:*:* | 6.0 (including) | 8.0.10020.0 (excluding) |
| cpe:2.3:a:eset:mail_security:*:*:*:*:*:domino:*:* | 6.0 (including) | 8.0.14011.0 (excluding) |
| cpe:2.3:a:eset:nod32_antivirus:*:*:*:*:*:windows:*:* | 11.2 (including) | 15.1.12.0 (excluding) |
| cpe:2.3:a:eset:security:*:*:*:*:*:sharepoint_server:*:* | 6.0 (including) | 8.0.15009.0 (excluding) |
| cpe:2.3:a:eset:server_security:*:*:*:*:*:azure:*:* | 6.0 (including) | |
| cpe:2.3:a:eset:server_security:*:*:*:*:*:windows_server:*:* | 8.0 (including) | 9.0.12012.0 (excluding) |
| cpe:2.3:a:eset:smart_security:*:*:*:*:premium:windows:*:* | 11.2 (including) | 15.1.12.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



