CVE-2016-9892
Last modified
CVE-2016-9892 is a vulnerability of currently unknown severity. The esets_daemon service in ESET Endpoint Antivirus for macOS before 6.4.168.0 and Endpoint Security for macOS before 6.4.168.0 does not properly verify X.509 certificates from the edf.eset.com SSL server, which allows man-in-the-middle attackers to spoof this server and provide crafted responses to license activation requests via a self-signed certificate. NOTE: this issue can be combined with CVE-2016-0718 to execute arbitrary code remotely as root.. EPSS estimates a 1.66% chance of exploitation in the next 30 days.
Description
The esets_daemon service in ESET Endpoint Antivirus for macOS before 6.4.168.0 and Endpoint Security for macOS before 6.4.168.0 does not properly verify X.509 certificates from the edf.eset.com SSL server, which allows man-in-the-middle attackers to spoof this server and provide crafted responses to license activation requests via a self-signed certificate. NOTE: this issue can be combined with CVE-2016-0718 to execute arbitrary code remotely as root.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Eset | Endpoint Antivirus | 6.3.70.1 |
| Eset | Endpoint Security | 6.3.70.1 |
References
- http://packetstormsecurity.com/files/141350/ESET-Endpoint-Antivirus-6-Remote-Code-Execution.htmlExploit, Third Party Advisory
- http://seclists.org/fulldisclosure/2017/Feb/68Exploit, Mailing List
- http://support.eset.com/ca6333/Vendor Advisory
- http://www.securityfocus.com/bid/96462Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/141350/ESET-Endpoint-Antivirus-6-Remote-Code-Execution.htmlExploit, Third Party Advisory
- http://seclists.org/fulldisclosure/2017/Feb/68Exploit, Mailing List
- http://support.eset.com/ca6333/Vendor Advisory
- http://www.securityfocus.com/bid/96462Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-9892?
How severe is CVE-2016-9892?
How do I fix CVE-2016-9892?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-9884Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2016-9885An issue was discovered in Pivotal GemFire for PCF 1.6.x ver…
- CVE-2016-9886Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2016-9888An error within the "tar_directory_for_file()" function (gsf…
- CVE-2016-9889Some forms with the parameter geo_zoomlevel_to_found_locatio…
- CVE-2016-9891Cross-site scripting (XSS) vulnerability in admin/media.php …
- CVE-2016-9893Memory safety bugs were reported in Thunderbird 45.5. Some o…
- CVE-2016-9894A buffer overflow in SkiaGl caused when a GrGLBuffer is trun…
- CVE-2016-9895Event handlers on "marquee" elements were executed despite a…
- CVE-2016-9896Use-after-free while manipulating the "navigator" object wit…
- CVE-2016-9897Memory corruption resulting in a potentially exploitable cra…
- CVE-2016-9898Use-after-free resulting in potentially exploitable crash wh…
Are you affected by CVE-2016-9892?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
