7.8

CVE-2021-37852

LPE in ESET products for Windows

ESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attacker to escalate privileges in the context of NT AUTHORITY\SYSTEM.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Eset ≫ Endpoint Antivirus SwPlatform windows Version >= 6.6.2046.0 < 7.3.2055.0
Eset ≫ Endpoint Antivirus SwPlatform windows Version >= 8.0 < 8.0.2028.3
Eset ≫ Endpoint Antivirus SwPlatform windows Version >= 8.1 < 8.1.2031.4
Eset ≫ Endpoint Antivirus SwPlatform windows Version >= 9.0 < 9.0.2032.6
Eset ≫ Endpoint Security SwPlatform windows Version >= 6.6.2046.0 < 7.3.2055.0
Eset ≫ Endpoint Security SwPlatform windows Version >= 8.0 < 8.0.2028.3
Eset ≫ Endpoint Security SwPlatform windows Version >= 8.1 < 8.1.2031.4
Eset ≫ Endpoint Security SwPlatform windows Version >= 9.0 < 9.0.2032.6
Eset ≫ File Security SwPlatform windows_server Version >= 7.0.12014.0 <= 7.3.12006.0
Eset ≫ Internet Security SwPlatform windows Version >= 10.0.337.1 < 15.0.18.0
Eset ≫ Mail Security SwPlatform exchange_server Version >= 7.0.10019 < 7.3.10014.0
Eset ≫ Mail Security SwPlatform domino Version >= 7.0.14008.0 < 7.3.14003.0
Eset ≫ Mail Security SwPlatform domino Version >= 8.0 < 8.0.14006.0
Eset ≫ Mail Security SwPlatform exchange_server Version >= 8.0.10012.0 < 8.0.10018.0
Eset ≫ Nod32 Antivirus SwPlatform windows Version >= 10.0.337.1 <= 15.0.18.0
Eset ≫ Security SwPlatform sharepoint Version >= 7.0.15008.0 <= 8.0.15004.0
Eset ≫ Server Security SwEdition azure Version >= 7.0.12016.1002 <= 7.2.12004.1000
Eset ≫ Server Security Version 8.0.12003.0 SwPlatform windows_server
Eset ≫ Server Security Version 8.0.12003.1 SwPlatform windows_server
Eset ≫ Smart Security SwEdition - SwPlatform windows Version >= 10.0.337.1 <= 15.0.18.0
Eset ≫ Smart Security SwEdition premium SwPlatform windows Version >= 10.0.337.1 <= 15.0.18.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.6% 0.456
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
security@eset.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

https://support.eset.com/en/ca8223-local-privilege-escalation-vulnerability-fixed-in-eset-products-for-windows
Vendor Advisory
https://www.zerodayinitiative.com/advisories/ZDI-22-148/
Third Party Advisory
VDB Entry