CVE-2023-7043

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Jan 31, 2024
Updated: Feb 9, 2024
CWE ID 428

Summary

CVE-2023-7043 is a newly discovered vulnerability affecting ESET products. It allows an attacker to drop a prepared program in an unquoted service path, granting it the ability to execute with NT AUTHORITY\NetworkService permissions upon system reboot. This weakness could potentially enable code execution and subsequent unauthorized access to a vulnerable system. The unquoted service path increases the risk of malware injections and should be addressed promptly through software updates or workarounds provided by ESET.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • ESET NOD32
  • ESET Smart Security Premium
  • Eset Endpoint Antivirus

Affected Vendors

  • ESET Corporation