QID 376449
Date Published: 2022-04-14
QID 376449: ESET Endpoint Security Unnecessary Privileges Local Privilege Escalation Vulnerability
ESET Endpoint Antivirus is provides protection against ransomware and zero day threats with an easy to use cloud based console.
Affected Version:
ESET Endpoint Security for Windows from version 6.6.2046.0 to 7.3.2041.0 and versions 8.0.2028.0 8.0.2039.0 8.0.2044.0 8.1.2031.0 8.1.2037 9.0.2032.2.
The vulnerability results from allowing an untrusted process to impersonate the client of a pipe. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM.
Solution
Refer to vendor advisory Eset Endpoint Security
Vendor References
CVEs related to QID 376449
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ca8223 |
|