7.8

CVE-2021-37851

Local privilege escalation in Windows products of ESET allows user who is logged into the system to exploit repair feature of the installer to run malicious code with higher privileges. This issue affects: ESET, spol. s r.o. ESET NOD32 Antivirus 11.2 versions prior to 15.1.12.0. ESET, spol. s r.o. ESET Internet Security 11.2 versions prior to 15.1.12.0. ESET, spol. s r.o. ESET Smart Security Premium 11.2 versions prior to 15.1.12.0. ESET, spol. s r.o. ESET Endpoint Antivirus 6.0 versions prior to 9.0.2046.0; 6.0 versions prior to 8.1.2050.0; 6.0 versions prior to 8.0.2053.0. ESET, spol. s r.o. ESET Endpoint Security 6.0 versions prior to 9.0.2046.0; 6.0 versions prior to 8.1.2050.0; 6.0 versions prior to 8.0.2053.0. ESET, spol. s r.o. ESET Server Security for Microsoft Windows Server 8.0 versions prior to 9.0.12012.0. ESET, spol. s r.o. ESET File Security for Microsoft Windows Server 8.0.12013.0. ESET, spol. s r.o. ESET Mail Security for Microsoft Exchange Server 6.0 versions prior to 8.0.10020.0. ESET, spol. s r.o. ESET Mail Security for IBM Domino 6.0 versions prior to 8.0.14011.0. ESET, spol. s r.o. ESET Security for Microsoft SharePoint Server 6.0 versions prior to 8.0.15009.0.

Data is provided by the National Vulnerability Database (NVD)
EsetEndpoint Antivirus SwPlatformwindows Version >= 6.0 < 8.0.2053.0
EsetEndpoint Antivirus SwPlatformwindows Version >= 8.1 < 8.1.2050.0
EsetEndpoint Antivirus SwPlatformwindows Version >= 9.0 < 9.0.2046.0
EsetEndpoint Security SwPlatformwindows Version >= 6.0 < 8.0.2053.0
EsetEndpoint Security SwPlatformwindows Version >= 8.1 < 8.1.2050.0
EsetEndpoint Security SwPlatformwindows Version >= 9.0 < 9.0.2046.0
EsetFile Security SwPlatformwindows_server Version >= 6.0 < 8.0.12013.0
EsetInternet Security SwPlatformwindows Version >= 11.2 < 15.1.12.0
EsetMail Security SwPlatformexchange_server Version >= 6.0 < 8.0.10020.0
EsetMail Security SwPlatformdomino Version >= 6.0 < 8.0.14011.0
EsetNod32 Antivirus SwPlatformwindows Version >= 11.2 < 15.1.12.0
EsetSecurity SwPlatformsharepoint_server Version >= 6.0 < 8.0.15009.0
EsetServer Security SwPlatformazure Version >= 6.0
EsetServer Security SwPlatformwindows_server Version >= 8.0 < 9.0.12012.0
EsetSmart Security SwEditionpremium SwPlatformwindows Version >= 11.2 < 15.1.12.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.03% 0.078
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
security@eset.com 7.3 1.3 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CWE-280 Improper Handling of Insufficient Permissions or Privileges

The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.

CWE-755 Improper Handling of Exceptional Conditions

The product does not handle or incorrectly handles an exceptional condition.