CVE-2025-8352 Overview
CVE-2025-8352 is a resource allocation vulnerability affecting ESET PROTECT On-Prem. The flaw allows unauthenticated network attackers to trigger excessive CPU and RAM consumption, creating conditions for a Denial-of-Service (DoS) attack. The underlying weakness is classified as [CWE-770] (Allocation of Resources Without Limits or Throttling).
ESET has released fixed versions through its customer advisory. The vulnerability requires no authentication, no user interaction, and is reachable over the network, which lowers the barrier for exploitation against exposed management infrastructure.
Critical Impact
Unauthenticated remote attackers can exhaust CPU and memory on the ESET PROTECT On-Prem server, disrupting centralized endpoint management and security operations.
Affected Products
- ESET PROTECT On-Prem (versions prior to the fixed release documented in the ESET customer advisory)
Discovery Timeline
- 2026-10-06 - CVE CVE-2025-8352 published to NVD
- 2026-10-06 - Last updated in NVD database
Technical Details for CVE-2025-8352
Vulnerability Analysis
The vulnerability resides in request handling paths within ESET PROTECT On-Prem that process network input without enforcing upper bounds on resource usage. When attackers send crafted or high-volume requests, the server allocates CPU cycles and memory without applying throttling, quotas, or rate limits.
Sustained exploitation forces the management server into a degraded state. Administrators lose timely visibility into endpoint telemetry, and automated response actions that depend on the console become unreliable. Impact is limited to availability; confidentiality and integrity are not affected based on the CVSS vector.
Root Cause
The root cause is improper enforcement of resource limits, tracked under [CWE-770]. The affected component accepts network input and processes it in a way that scales resource consumption with attacker-controlled factors. Without caps on concurrent requests, allocation sizes, or processing time, a modest volume of requests can exhaust server capacity.
Attack Vector
Attackers exploit the issue over the network against reachable ESET PROTECT On-Prem endpoints. No credentials or user interaction are required. An attacker generates traffic patterns that the server processes expensively, driving CPU and memory to saturation. Operators of internet-exposed or weakly segmented management servers face the highest risk.
No public proof-of-concept exploit is listed in the enriched data, and the vulnerability is not present on the CISA Known Exploited Vulnerabilities list. Refer to the ESET Customer Advisory on DoS Vulnerability for vendor-authoritative technical context.
Detection Methods for CVE-2025-8352
Indicators of Compromise
- Sustained spikes in CPU and RAM utilization on the ESET PROTECT On-Prem host without a corresponding scheduled task or policy push.
- Management console slowdowns, timeouts, or agent check-in failures across managed endpoints.
- Unusually high volumes of inbound connections to the ESET PROTECT management ports from a narrow set of source addresses.
Detection Strategies
- Baseline normal CPU, memory, and connection counts for the management server and alert on sustained deviations.
- Inspect reverse proxy or load balancer logs in front of ESET PROTECT for anomalous request rates or oversized payloads.
- Correlate agent disconnect events with management server health metrics to identify DoS-induced outages.
Monitoring Recommendations
- Forward ESET PROTECT server metrics and web/API logs to a centralized analytics platform for anomaly detection.
- Enable alerting on process-level resource exhaustion for the ESET PROTECT service account.
- Track network flow data to the management server interface to identify volumetric or low-and-slow abuse patterns.
How to Mitigate CVE-2025-8352
Immediate Actions Required
- Upgrade ESET PROTECT On-Prem to the fixed version identified in the ESET Customer Advisory on DoS Vulnerability.
- Restrict network access to the management console and agent communication ports to trusted administrative subnets.
- Review perimeter exposure and remove any direct internet accessibility of the management server.
Patch Information
ESET has released a fixed build of ESET PROTECT On-Prem that addresses the resource allocation issue. Administrators should review the vendor advisory for exact fixed version numbers and follow the documented upgrade path for their deployment topology.
Workarounds
- Place the ESET PROTECT On-Prem server behind a reverse proxy or web application firewall that enforces per-source rate limiting.
- Apply firewall ACLs to limit inbound connections to authorized management workstations and managed endpoint subnets.
- Configure OS-level resource controls, such as cgroups on Linux or Job Objects on Windows, to cap memory consumption by the ESET PROTECT service process.
# Example: restrict access to ESET PROTECT management port with iptables
iptables -A INPUT -p tcp --dport 2223 -s 10.0.0.0/24 -j ACCEPT
iptables -A INPUT -p tcp --dport 2223 -j DROP
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.