Vulnerability Intelligence Report
Denial-of-service vulnerability in ESET PROTECT On-Prem
CVE-2025-8352
Allocation of resources without limits or throttling vulnerability in ESET PROTECT On-Prem increased resource consumption (CPU and RAM), leading to conditions for a Denial-of-Service attack.
No Active Exploit Signals
CVSS Base Score
6.9
MEDIUM
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-770 ↗CWE-770 Allocation of resources without limits or throttling
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| ESET spol. s.r.o | ESET PROTECT On-Prem | 0 <= 12.1.9.0 (with Web Console 12.1.252.0) (affected), 0 <= 12.0.13.0 (with Web Console 12.0.289.0) (affected), 0 <= 11.1.16.0 (with Web Console 11.1.149.0) (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | ESET, spol. s r.o. · Vendor · Slovak Republic |
| Reserved | 2025-07-30T13:00:31 |
| Published | 2026-10-06T14:50:55 |
| Patch Date | 2025-08-22 |
| Last Updated | 2026-10-06T17:20:07 |
Community Chatter & Buzz