7.8

CVE-2021-37852

ESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attacker to escalate privileges in the context of NT AUTHORITY\SYSTEM.

Data is provided by the National Vulnerability Database (NVD)
EsetEndpoint Antivirus SwPlatformwindows Version >= 6.6.2046.0 < 7.3.2055.0
EsetEndpoint Antivirus SwPlatformwindows Version >= 8.0 < 8.0.2028.3
EsetEndpoint Antivirus SwPlatformwindows Version >= 8.1 < 8.1.2031.4
EsetEndpoint Antivirus SwPlatformwindows Version >= 9.0 < 9.0.2032.6
EsetEndpoint Security SwPlatformwindows Version >= 6.6.2046.0 < 7.3.2055.0
EsetEndpoint Security SwPlatformwindows Version >= 8.0 < 8.0.2028.3
EsetEndpoint Security SwPlatformwindows Version >= 8.1 < 8.1.2031.4
EsetEndpoint Security SwPlatformwindows Version >= 9.0 < 9.0.2032.6
EsetFile Security SwPlatformwindows_server Version >= 7.0.12014.0 <= 7.3.12006.0
EsetInternet Security SwPlatformwindows Version >= 10.0.337.1 < 15.0.18.0
EsetMail Security SwPlatformexchange_server Version >= 7.0.10019 < 7.3.10014.0
EsetMail Security SwPlatformdomino Version >= 7.0.14008.0 < 7.3.14003.0
EsetMail Security SwPlatformdomino Version >= 8.0 < 8.0.14006.0
EsetMail Security SwPlatformexchange_server Version >= 8.0.10012.0 < 8.0.10018.0
EsetNod32 Antivirus SwPlatformwindows Version >= 10.0.337.1 <= 15.0.18.0
EsetSecurity SwPlatformsharepoint Version >= 7.0.15008.0 <= 8.0.15004.0
EsetServer Security SwEditionazure Version >= 7.0.12016.1002 <= 7.2.12004.1000
EsetServer Security Version8.0.12003.0 SwPlatformwindows_server
EsetServer Security Version8.0.12003.1 SwPlatformwindows_server
EsetSmart Security SwEdition- SwPlatformwindows Version >= 10.0.337.1 <= 15.0.18.0
EsetSmart Security SwEditionpremium SwPlatformwindows Version >= 10.0.337.1 <= 15.0.18.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.102
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
security@eset.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.