Installation file of ESET security products on Windows allow an attacker to misuse to delete an arbitrary file without having the permissions to do so.
History

Fri, 11 Jul 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00011}


Fri, 11 Jul 2025 06:45:00 +0000

Type Values Removed Values Added
Description Installation file of ESET security products on Windows allow an attacker to misuse to delete an arbitrary file without having the permissions to do so.
Title Arbitrary file deletion vulnerability in ESET product installers
Weaknesses CWE-269
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ESET

Published: 2025-07-11T06:40:28.636Z

Updated: 2025-07-11T16:11:55.884Z

Reserved: 2025-05-21T09:28:16.965Z

Link: CVE-2025-5028

cve-icon Vulnrichment

Updated: 2025-07-11T16:11:24.291Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-11T07:15:23.940

Modified: 2025-07-15T13:14:49.980

Link: CVE-2025-5028

cve-icon Redhat

No data.