A flaw in ESET Endpoint Antivirus is exploitable to get remote root execution on Apple Mac systems via Man-In-The-Middle (MiTM) attacks. The attackers can get root-level remote code execution on a Mac by intercepting the antivirus packages connection to company backend servers. The attack is possible due to the presence of a buffer overflow vulnerability in the XML library tracked as CVE-2016-0718. An attacker can intercept the request and send to the ESET antivirus a self-signed HTTPS certificate, then the esets_daemon service parses the response as an XML document.”]
Source: http://securityaffairs.co/wordpress/56744/hacking/eset-endpoint-antivirus-flaw.html