ZDI-24-182: ESET Smart Security Premium ekrn Link Following Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of ESET Smart Security Premium. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-0353.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-182?
The severity of ZDI-24-182 is significant, as it allows privilege escalation on affected installations.
How do I fix ZDI-24-182?
To fix ZDI-24-182, update ESET Smart Security Premium to the latest version provided by the vendor.
Who is affected by ZDI-24-182?
ZDI-24-182 affects users of ESET Smart Security Premium who have not applied recent patches.
What type of attack does ZDI-24-182 involve?
ZDI-24-182 involves local attacks where an attacker escalates privileges on the affected system.
What prerequisites are needed to exploit ZDI-24-182?
An attacker must first execute low-privileged code on the target system to exploit ZDI-24-182.