Back to Database
Status published
Low
CVE-2023-7043
Unquoted path privilege vulnerability in ESET products for Windows
Vulnerability Description
Unquoted service path in ESET products allows to drop a prepared program to a specific location and run on boot with the NT AUTHORITY\NetworkService permissions.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-7043
Credits & Attribution
No credits recorded in the NVD database.
References
More from ESET, spol. s r.o.
View All →CVE-2024-7400
Local privilege escalation in ESET products for Windows
High
8.5
CVE-2024-6654
Denial of Service vulnerability in ESET products for macOS
Medium
6.8
CVE-2024-2003
Local Privilege Escalation in Quarantine of ESET products for Windows
High
7.3
CVE-2024-11859
DLL Search Order Hijacking in ESET products for Windows
High
8.4
CVE-2024-0353
Local privilege escalation in Windows products
High
7.8
Affected Vendor
ESET, spol. s r.o.
View all reports →Affected Software
ESET Endpoint Security, ESET Endpoint Antivirus, ESET NOD32 Antivirus, ESET Internet Security, ESET Smart Security Premium, ESET Mail Security for Microsoft Exchange Server
Vulnerable Versions:
10.1.2046.x, 16.1.14.0, 10.1.10012.0
Timeline
Official Publish:
January 31st, 2024
Last Modified:
October 17th, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N