CVE-2023-7043: Unquoted path privilege vulnerability in ESET products for Windows
Unquoted service path in ESET products allows to
drop a prepared program to a specific location and run on boot with the
NT AUTHORITY\NetworkService permissions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-7043?
CVE-2023-7043 is considered a medium severity vulnerability due to the risk of unauthorized program execution with elevated permissions.
How do I fix CVE-2023-7043?
To fix CVE-2023-7043, ensure that you update your ESET software to a version that addresses this unquoted service path vulnerability.
Which ESET products are affected by CVE-2023-7043?
CVE-2023-7043 affects various versions of ESET Endpoint Antivirus, Endpoint Security, Internet Security, Mail Security for Microsoft Exchange Server, NOD32 Antivirus, and Smart Security Premium.
What permissions can be exploited in CVE-2023-7043?
CVE-2023-7043 can be exploited to execute a malicious program with NT AUTHORITY\NetworkService permissions.
Is user intervention required to exploit CVE-2023-7043?
Yes, exploiting CVE-2023-7043 requires an attacker to place a prepared program in a specific location before it can be executed on boot.