CVE-2018-0649: Critical severity eset compusec vulnerability
Untrusted search path vulnerability in the installers of multiple Canon IT Solutions Inc. software programs (ESET Smart Security Premium, ESET Internet Security, ESET Smart Security, ESET NOD32 Antivirus, DESlock+ Pro, and CompuSec (all programs except packaged ones)) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-0649.
Which software programs are affected by this vulnerability?
The vulnerability affects ESET Smart Security Premium, ESET Internet Security, ESET Smart Security, ESET NOD32 Antivirus, DESlock+ Pro, and CompuSec (all programs except packaged ones) developed by Canon IT Solutions Inc.
What is the severity of the vulnerability?
The severity of the vulnerability is critical.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by using an untrusted search path in the installers of the affected software, allowing them to gain unauthorized privileges.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the following references: [http://jvn.jp/en/jp/JVN41452671/index.html](http://jvn.jp/en/jp/JVN41452671/index.html) and [https://eset-support.canon-its.jp/faq/show/10720?site_domain=default](https://eset-support.canon-its.jp/faq/show/10720?site_domain=default).