Founded in "1992, ESET is a global provider of security software for enterprises and consumers. ESET's award-winning, antivirus software system, NOD32, provides real-time protection from known and unknown viruses, spyware, rootkits and other malware". Multiple vulnerabilities have been found in the file parsing engine of NOD32 antivirus.
Vulnerable Systems:
* NOD32 Antivirus version 1.1742 and prior
Immune Systems:
* NOD32 Antivirus version 1.1743
In detail, the following flaw was determined:
- Divide by Zero in .CHM file parsing.
- Heap Overflow through Integer Overflow in .DOC File Parsing
The .DOC problem can lead to remote arbitrary code execution if an attacker carefully crafts a file that exploits the aforementioned vulnerabilities. The vulnerabilities are present in NOD32 Antivirus software versions prior to the update v.1.1743.
Solution:
The vulnerabilities were reported on Aug 24 and an update has been issued on September 08 to solve these vulnerabilities through the regular update mechanism.