CVE-2020-11446: Eset Antivirus And Antispyware
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
ESET Antivirus and Antispyware Module module 1553 through 1560 allows a user with limited access rights to create hard links in some ESET directories and then force the product to write through these links into files that would normally not be write-able by the user, thus achieving privilege escalation.
Affected products
- Eset Antivirus And Antispyware: from 1553, up to and including 1560
- Eset Endpoint Antivirus: affected versions not specified
- Eset Endpoint Security: affected versions not specified
- Eset File Security: affected versions not specified
- Eset Internet Security: affected versions not specified
- Eset Mail Security: affected versions not specified
- Eset NOD32 Antivirus: affected versions not specified
- Eset Smart Security: affected versions not specified
Published 2020-04-29. Last modified 2026-06-17.