7.8
CVE-2021-37852
- EPSS 0.6%
- Veröffentlicht 09.02.2022 06:15:06
- Zuletzt bearbeitet 21.11.2024 06:15:58
- Erkennungen
LPE in ESET products for Windows
ESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attacker to escalate privileges in the context of NT AUTHORITY\SYSTEM.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Eset ≫ Endpoint Antivirus SwPlatform windows Version >= 6.6.2046.0 < 7.3.2055.0
Eset ≫ Endpoint Antivirus SwPlatform windows Version >= 8.0 < 8.0.2028.3
Eset ≫ Endpoint Antivirus SwPlatform windows Version >= 8.1 < 8.1.2031.4
Eset ≫ Endpoint Antivirus SwPlatform windows Version >= 9.0 < 9.0.2032.6
Eset ≫ Endpoint Security SwPlatform windows Version >= 6.6.2046.0 < 7.3.2055.0
Eset ≫ Endpoint Security SwPlatform windows Version >= 8.0 < 8.0.2028.3
Eset ≫ Endpoint Security SwPlatform windows Version >= 8.1 < 8.1.2031.4
Eset ≫ Endpoint Security SwPlatform windows Version >= 9.0 < 9.0.2032.6
Eset ≫ File Security SwPlatform windows_server Version >= 7.0.12014.0 <= 7.3.12006.0
Eset ≫ Internet Security SwPlatform windows Version >= 10.0.337.1 < 15.0.18.0
Eset ≫ Mail Security SwPlatform exchange_server Version >= 7.0.10019 < 7.3.10014.0
Eset ≫ Mail Security SwPlatform domino Version >= 7.0.14008.0 < 7.3.14003.0
Eset ≫ Mail Security SwPlatform domino Version >= 8.0 < 8.0.14006.0
Eset ≫ Mail Security SwPlatform exchange_server Version >= 8.0.10012.0 < 8.0.10018.0
Eset ≫ Nod32 Antivirus SwPlatform windows Version >= 10.0.337.1 <= 15.0.18.0
Eset ≫ Server Security SwEdition azure Version >= 7.0.12016.1002 <= 7.2.12004.1000
Eset ≫ Server Security Version 8.0.12003.0 SwPlatform windows_server
Eset ≫ Server Security Version 8.0.12003.1 SwPlatform windows_server
Eset ≫ Smart Security SwEdition - SwPlatform windows Version >= 10.0.337.1 <= 15.0.18.0
Eset ≫ Smart Security SwEdition premium SwPlatform windows Version >= 10.0.337.1 <= 15.0.18.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.6% | 0.456 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
| security@eset.com | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
https://support.eset.com/en/ca8223-local-privilege-escalation-vulnerability-fixed-in-eset-products-for-windows
https://www.zerodayinitiative.com/advisories/ZDI-22-148/