CVE-2018-0649 Vulnerability Details

  /     /     /  

CVE-2018-0649 Metadata Quick Info

CVE Published: 07/09/2018 | CVE Updated: 05/08/2024 | CVE Year: 2018
Source: jpcert | Vendor: Canon IT Solutions Inc. | Product: The installers of multiple Canon IT Solutions Inc. software programs
Status : PUBLISHED

CVE-2018-0649 Description

Untrusted search path vulnerability in the installers of multiple Canon IT Solutions Inc. software programs (ESET Smart Security Premium, ESET Internet Security, ESET Smart Security, ESET NOD32 Antivirus, DESlock+ Pro, and CompuSec (all programs except packaged ones)) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Untrusted search path vulnerability
Source: Canon IT Solutions Inc.

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).