QID 376449

Date Published: 2022-04-14

QID 376449: ESET Endpoint Security Unnecessary Privileges Local Privilege Escalation Vulnerability

ESET Endpoint Antivirus is provides protection against ransomware and zero day threats with an easy to use cloud based console.

Affected Version:
ESET Endpoint Security for Windows from version 6.6.2046.0 to 7.3.2041.0 and versions 8.0.2028.0 8.0.2039.0 8.0.2044.0 8.1.2031.0 8.1.2037 9.0.2032.2.

The vulnerability results from allowing an untrusted process to impersonate the client of a pipe. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution
    Refer to vendor advisory Eset Endpoint Security

    CVEs related to QID 376449

    Software Advisories
    Advisory ID Software Component Link
    ca8223 URL Logo help.eset.com/latestVersions/?lang=en