CVE-2014-4973
The ESET Personal Firewall NDIS filter (EpFwNdis.sys) driver in the Firewall Module Build 1183 (20140214) and earlier in ESET Smart Security and ESET Endpoint Security products 5.0 through 7.0 allows local users to gain privileges via a crafted argument…
Does this matter?
Lower severity and a low EPSS score (1.31%). Track it; it rarely justifies an emergency change on its own.
Description
The ESET Personal Firewall NDIS filter (EpFwNdis.sys) driver in the Firewall Module Build 1183 (20140214) and earlier in ESET Smart Security and ESET Endpoint Security products 5.0 through 7.0 allows local users to gain privileges via a crafted argument to a 0x830020CC IOCTL call.
- CVSS 2.0
- 6.9 MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 1.31% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- eset/smart security · eset/endpoint security
- Source
- cve@mitre.org
References
- http://seclists.org/fulldisclosure/2014/Aug/52
- https://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-4973/Exploit
- http://seclists.org/fulldisclosure/2014/Aug/52
- https://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-4973/Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.