CVE-2014-4974: Infoleak
The ESET Personal Firewall NDIS filter (EpFwNdis.sys) kernel mode driver, aka Personal Firewall module before Build 1212 (20140609), as used in multiple ESET products 5.0 through 7.0, allows local users to obtain sensitive information from kernel memory via crafted IOCTL calls.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4974?
CVE-2014-4974 has been classified as a high severity vulnerability due to its potential to expose sensitive kernel memory information.
How do I fix CVE-2014-4974?
To fix CVE-2014-4974, users should update to a version of the ESET Personal Firewall NDIS filter that is Build 1212 or later.
Who is affected by CVE-2014-4974?
CVE-2014-4974 affects users of ESET Personal Firewall versions 5.0 through 7.0 prior to Build 1212.
What type of vulnerability is CVE-2014-4974?
CVE-2014-4974 is a local privilege escalation vulnerability that allows attackers to access sensitive kernel memory.
Can CVE-2014-4974 be exploited remotely?
CVE-2014-4974 cannot be exploited remotely as it requires local access to the affected system.