First published: Tue Nov 04 2014(Updated: )
The ESET Personal Firewall NDIS filter (EpFwNdis.sys) kernel mode driver, aka Personal Firewall module before Build 1212 (20140609), as used in multiple ESET products 5.0 through 7.0, allows local users to obtain sensitive information from kernel memory via crafted IOCTL calls.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ESET Personal Firewall NDIS filter | <=1183_\(20140214\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4974 has been classified as a high severity vulnerability due to its potential to expose sensitive kernel memory information.
To fix CVE-2014-4974, users should update to a version of the ESET Personal Firewall NDIS filter that is Build 1212 or later.
CVE-2014-4974 affects users of ESET Personal Firewall versions 5.0 through 7.0 prior to Build 1212.
CVE-2014-4974 is a local privilege escalation vulnerability that allows attackers to access sensitive kernel memory.
CVE-2014-4974 cannot be exploited remotely as it requires local access to the affected system.