Executable installers are vulnerable^WEVIL (case 13): ESET NOD32 antivirus installer allows remote code execution with escalation of privilege

Posted by Stefan Kanthak on Dec 21

Hi @ll,

the executable installer [°] of ESET’s NOD32 antivirus,
eset_nod32_antivirus_live_installer_.exe, loads and executes
(at least) the rogue/bogus/malicious Cabinet.dll and DbgHelp.dll
eventually found in the directory it is started from [‘] (the
“application directory”).

For software downloaded with a web browser this is typically the
“Downloads” directory: see
<…

Leave a Reply