First published: Thu Mar 05 2020(Updated: )
The ESET AV parsing engine allows virus-detection bypass via a crafted BZ2 Checksum field in an archive. This affects versions before 1294 of Smart Security Premium, Internet Security, NOD32 Antivirus, Cyber Security Pro (macOS), Cyber Security (macOS), Mobile Security for Android, Smart TV Security, and NOD32 Antivirus 4 for Linux Desktop.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eset Cyber Security | <1294 | |
Eset Cyber Security | <1294 | |
Eset Mobile Security | <1294 | |
Eset Nod32 Antivirus | <1294 | |
Eset Nod32 Antivirus | =4 | |
ESET Smart Security | <1294 | |
ESET Smart Security | <1294 | |
Eset Smart Tv Security | <1294 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10180 is a vulnerability in the ESET AV parsing engine that allows virus-detection bypass via a crafted BZ2 Checksum field in an archive.
Versions before 1294 of Smart Security Premium, Internet Security, NOD32 Antivirus, Cyber Security Pro (macOS), Cyber Security (macOS), Mobile Security for Android, and Smart TV Security are affected by CVE-2020-10180.
The severity of CVE-2020-10180 is critical with a CVSS score of 9.8.
To fix the vulnerability, you should update your ESET software to version 1294 or later.
Yes, you can find more information about CVE-2020-10180 at the following reference: [https://blog.zoller.lu/p/tzo-11-2020-eset-generic-malformed.html](https://blog.zoller.lu/p/tzo-11-2020-eset-generic-malformed.html)