CVE-2014-4974 – Kernel Memory Leak in ESET Multiple Windows Products
Vulnerability title: Kernel Memory Leak in ESET Multiple Windows Products
Product: Multiple Windows Products
Affected version: 5.0 – 7.0
Fixed version: Build 1212
Reported by: Kyriakos Economou
The latest, and earlier versions, of ESET Smart Security and ESET Endpoint Security products for Windows XP OS allow any local user to leak privileged information from kernel memory by exploiting a vulnerability in the ESET Personal Firewall NDIS filter (EpFwNdis.sys) kernel mode driver also known as Personal Firewall module: Build 1183 (20140214) and prior.
The vulnerability is caused by improper validation for some IOCTLs. This issue is addressed in Firewall Module Build 1212 (20140609) by allowing by default only Administrator users to interact with the driver through IOCTLs.