Skip to main content

CVE-2025-8352: ESET PROTECT On-Prem DOS Vulnerability

CVE-2025-8352 is a denial-of-service flaw in ESET PROTECT On-Prem caused by unlimited resource allocation that enables attackers to exhaust CPU and RAM. This article covers technical details, impact analysis, and mitigation.

Published:

CVE-2025-8352 Overview

CVE-2025-8352 is a resource allocation vulnerability affecting ESET PROTECT On-Prem. The flaw allows unauthenticated network attackers to trigger excessive CPU and RAM consumption, creating conditions for a Denial-of-Service (DoS) attack. The underlying weakness is classified as [CWE-770] (Allocation of Resources Without Limits or Throttling).

ESET has released fixed versions through its customer advisory. The vulnerability requires no authentication, no user interaction, and is reachable over the network, which lowers the barrier for exploitation against exposed management infrastructure.

Critical Impact

Unauthenticated remote attackers can exhaust CPU and memory on the ESET PROTECT On-Prem server, disrupting centralized endpoint management and security operations.

Affected Products

  • ESET PROTECT On-Prem (versions prior to the fixed release documented in the ESET customer advisory)

Discovery Timeline

  • 2026-10-06 - CVE CVE-2025-8352 published to NVD
  • 2026-10-06 - Last updated in NVD database

Technical Details for CVE-2025-8352

Vulnerability Analysis

The vulnerability resides in request handling paths within ESET PROTECT On-Prem that process network input without enforcing upper bounds on resource usage. When attackers send crafted or high-volume requests, the server allocates CPU cycles and memory without applying throttling, quotas, or rate limits.

Sustained exploitation forces the management server into a degraded state. Administrators lose timely visibility into endpoint telemetry, and automated response actions that depend on the console become unreliable. Impact is limited to availability; confidentiality and integrity are not affected based on the CVSS vector.

Root Cause

The root cause is improper enforcement of resource limits, tracked under [CWE-770]. The affected component accepts network input and processes it in a way that scales resource consumption with attacker-controlled factors. Without caps on concurrent requests, allocation sizes, or processing time, a modest volume of requests can exhaust server capacity.

Attack Vector

Attackers exploit the issue over the network against reachable ESET PROTECT On-Prem endpoints. No credentials or user interaction are required. An attacker generates traffic patterns that the server processes expensively, driving CPU and memory to saturation. Operators of internet-exposed or weakly segmented management servers face the highest risk.

No public proof-of-concept exploit is listed in the enriched data, and the vulnerability is not present on the CISA Known Exploited Vulnerabilities list. Refer to the ESET Customer Advisory on DoS Vulnerability for vendor-authoritative technical context.

Detection Methods for CVE-2025-8352

Indicators of Compromise

  • Sustained spikes in CPU and RAM utilization on the ESET PROTECT On-Prem host without a corresponding scheduled task or policy push.
  • Management console slowdowns, timeouts, or agent check-in failures across managed endpoints.
  • Unusually high volumes of inbound connections to the ESET PROTECT management ports from a narrow set of source addresses.

Detection Strategies

  • Baseline normal CPU, memory, and connection counts for the management server and alert on sustained deviations.
  • Inspect reverse proxy or load balancer logs in front of ESET PROTECT for anomalous request rates or oversized payloads.
  • Correlate agent disconnect events with management server health metrics to identify DoS-induced outages.

Monitoring Recommendations

  • Forward ESET PROTECT server metrics and web/API logs to a centralized analytics platform for anomaly detection.
  • Enable alerting on process-level resource exhaustion for the ESET PROTECT service account.
  • Track network flow data to the management server interface to identify volumetric or low-and-slow abuse patterns.

How to Mitigate CVE-2025-8352

Immediate Actions Required

  • Upgrade ESET PROTECT On-Prem to the fixed version identified in the ESET Customer Advisory on DoS Vulnerability.
  • Restrict network access to the management console and agent communication ports to trusted administrative subnets.
  • Review perimeter exposure and remove any direct internet accessibility of the management server.

Patch Information

ESET has released a fixed build of ESET PROTECT On-Prem that addresses the resource allocation issue. Administrators should review the vendor advisory for exact fixed version numbers and follow the documented upgrade path for their deployment topology.

Workarounds

  • Place the ESET PROTECT On-Prem server behind a reverse proxy or web application firewall that enforces per-source rate limiting.
  • Apply firewall ACLs to limit inbound connections to authorized management workstations and managed endpoint subnets.
  • Configure OS-level resource controls, such as cgroups on Linux or Job Objects on Windows, to cap memory consumption by the ESET PROTECT service process.
bash
# Example: restrict access to ESET PROTECT management port with iptables
iptables -A INPUT -p tcp --dport 2223 -s 10.0.0.0/24 -j ACCEPT
iptables -A INPUT -p tcp --dport 2223 -j DROP

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.