CVE-2016-9892
Last modified
CVE-2016-9892 is a vulnerability of currently unknown severity. The esets_daemon service in ESET Endpoint Antivirus for macOS before 6.4.168.0 and Endpoint Security for macOS before 6.4.168.0 does not properly verify X.509 certificates from the edf.eset.com SSL server, which allows man-in-the-middle attackers to spoof this server and provide crafted responses to license activation requests via a self-signed certificate. NOTE: this issue can be combined with CVE-2016-0718 to execute arbitrary code remotely as root.. EPSS estimates a 1.66% chance of exploitation in the next 30 days.
Description
The esets_daemon service in ESET Endpoint Antivirus for macOS before 6.4.168.0 and Endpoint Security for macOS before 6.4.168.0 does not properly verify X.509 certificates from the edf.eset.com SSL server, which allows man-in-the-middle attackers to spoof this server and provide crafted responses to license activation requests via a self-signed certificate. NOTE: this issue can be combined with CVE-2016-0718 to execute arbitrary code remotely as root.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Eset | Endpoint Antivirus | 6.3.70.1 |
| Eset | Endpoint Security | 6.3.70.1 |
References
- http://packetstormsecurity.com/files/141350/ESET-Endpoint-Antivirus-6-Remote-Code-Execution.htmlExploit, Third Party Advisory
- http://seclists.org/fulldisclosure/2017/Feb/68Exploit, Mailing List
- http://support.eset.com/ca6333/Vendor Advisory
- http://www.securityfocus.com/bid/96462Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/141350/ESET-Endpoint-Antivirus-6-Remote-Code-Execution.htmlExploit, Third Party Advisory
- http://seclists.org/fulldisclosure/2017/Feb/68Exploit, Mailing List
- http://support.eset.com/ca6333/Vendor Advisory
- http://www.securityfocus.com/bid/96462Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-9892?
How severe is CVE-2016-9892?
How do I fix CVE-2016-9892?
Are you affected by CVE-2016-9892?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
