CVE-2014-4973: Input Validation
The ESET Personal Firewall NDIS filter (EpFwNdis.sys) driver in the Firewall Module Build 1183 (20140214) and earlier in ESET Smart Security and ESET Endpoint Security products 5.0 through 7.0 allows local users to gain privileges via a crafted argument to a 0x830020CC IOCTL call.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4973?
CVE-2014-4973 has a medium severity level due to its potential for local privilege escalation.
How do I fix CVE-2014-4973?
To mitigate CVE-2014-4973, update to the latest version of ESET Smart Security or ESET Endpoint Security that addresses this vulnerability.
What are the affected versions in CVE-2014-4973?
CVE-2014-4973 affects ESET Smart Security versions 5.0 through 7.0 and ESET Endpoint Security versions 5.0.x.
Can CVE-2014-4973 be exploited remotely?
CVE-2014-4973 cannot be exploited remotely as it requires local user access to exploit the vulnerability.
What component of ESET is affected by CVE-2014-4973?
CVE-2014-4973 affects the ESET Personal Firewall NDIS filter driver (EpFwNdis.sys).