LPE in ESET products for Windows
CVE-2021-37852
7.8HIGH
What is CVE-2021-37852?
ESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attacker to escalate privileges in the context of NT AUTHORITY\SYSTEM.
Affected Version(s)
ESET Endpoint Antivirus for Windows 6.6.2046.0 <= 9.0.2032.4
ESET Endpoint Security for Windows 6.6.2046.0 <= 9.0.2032.4
ESET File Security for Microsoft Windows Server 7.0.12014.0 <= 7.3.12006.0
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Michael DePlante (@izobashi) of Trend Micro's Zero Day Initiative
