LPE in ESET products for Windows
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.8epss 0.6%
exploitation probability
0.6%top 53% of all CVEs
observed exploitation
nono source reports it
ESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attacker to escalate privileges in the context of NT AUTHORITY\SYSTEM.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
ESET · ESET Endpoint Antivirus for WindowsESET · ESET Endpoint Security for WindowsESET · ESET File Security for Microsoft Windows ServerESET · ESET Internet SecurityESET · ESET Mail Security for IBM DominoESET · ESET Mail Security for Microsoft Exchange ServerESET · ESET NOD32 AntivirusESET · ESET Security for Microsoft SharePoint ServerESET · ESET Server Security for Microsoft AzureESET · ESET Server Security for Microsoft Windows ServerESET · ESET Smart Security