CVE 5.1 MEDIUM

TOCTOU race condition vulnerability in ESET products on Windows_CVE-2025-2425

5.1 / 10
MEDIUM
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Description

Time-of-check to time-of-use race condition vulnerability potentially allowed an attacker to use the installed ESET security software to clear the content of an arbitrary file on the file system.

Basic Information

ID CVE-2025-2425
Source ESET
Published Jul 18, 2025 at 09:20
Modified Jul 18, 2025 at 11:37

Affected Product

Vendor ESET, spol. s.r.o
Product ESET NOD32 Antivirus
Affected Versions ESET, spol. s.r.o ESET NOD32 Antivirus 0
ESET, spol. s.r.o ESET Internet Security 0
ESET, spol. s.r.o ESET Smart Security Premium 0
ESET, spol. s.r.o ESET Security Ultimate 0
ESET, spol. s.r.o ESET Endpoint Antivirus for Windows 0
ESET, spol. s.r.o ESET Endpoint Antivirus for Windows 0
ESET, spol. s.r.o ESET Endpoint Security for Windows 0
ESET, spol. s.r.o ESET Endpoint Security for Windows 0
ESET, spol. s.r.o ESET Small Business Security 0
ESET, spol. s.r.o ESET Safe Server 0
ESET, spol. s.r.o ESET Server Security for Windows Server 0
ESET, spol. s.r.o ESET Server Security for Windows Server 0
ESET, spol. s.r.o ESET Mail Security for Microsoft Exchange Server 0
ESET, spol. s.r.o ESET Mail Security for Microsoft Exchange Server 0
ESET, spol. s.r.o ESET Security for Microsoft SharePoint Server 0
ESET, spol. s.r.o ESET Security for Microsoft SharePoint Server 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.