First published: Tue Feb 18 2020(Updated: )
ESET Archive Support Module before 1296 allows virus-detection bypass via a crafted Compression Information Field in a ZIP archive. This affects versions before 1294 of Smart Security Premium, Internet Security, NOD32 Antivirus, Cyber Security Pro (macOS), Cyber Security (macOS), Mobile Security for Android, Smart TV Security, and NOD32 Antivirus 4 for Linux Desktop.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eset Cyber Security | <1296 | |
Eset Cyber Security | <1296 | |
ESET Internet Security | <1296 | |
Eset Mobile Security | <1296 | |
Eset Nod32 Antivirus | <1296 | |
Eset Nod32 Antivirus | =4 | |
ESET Smart Security | <1296 | |
Eset Smart Tv Security | <1296 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9264 is a vulnerability in ESET Archive Support Module before version 1296 that allows virus-detection bypass via a crafted Compression Information Field in a ZIP archive.
Versions before 1296 of Eset Smart Security Premium, Internet Security, Nod32 Antivirus, Cyber Security Pro (macOS), Cyber Security (macOS), Mobile Security for Android, and Smart TV Security are affected.
The severity rating of CVE-2020-9264 is medium, with a severity value of 5.5.
To fix CVE-2020-9264, update to version 1296 or later of the affected ESET software.
You can find more information about CVE-2020-9264 at the following references: [Reference 1](http://seclists.org/fulldisclosure/2020/Feb/21), [Reference 2](https://blog.zoller.lu/p/tzo-11-2020-eset-generic-malformed.html), [Reference 3](https://support.eset.com/en/ca7387-modules-review-december-2019)