Back to Database
Status published
Medium
CVE-2025-2425
TOCTOU race condition vulnerability in ESET products on Windows
Vulnerability Description
Time-of-check to time-of-use race condition vulnerability potentially allowed an attacker to use the installed ESET security software to clear the content of an arbitrary file on the file system.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-2425
Credits & Attribution
No credits recorded in the NVD database.
Affected Vendor
ESET, spol. s.r.o
View all reports →Affected Software
ESET NOD32 Antivirus, ESET Internet Security, ESET Smart Security Premium, ESET Security Ultimate, ESET Endpoint Antivirus for Windows, ESET Endpoint Security for Windows, ESET Small Business Security, ESET Safe Server, ESET Server Security for Windows Server, ESET Mail Security for Microsoft Exchange Server, ESET Security for Microsoft SharePoint Server
Vulnerable Versions:
0
Timeline
Official Publish:
July 18th, 2025
Last Modified:
July 18th, 2025
Added to House:
July 22nd, 2026