ESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attacker to escalate privileges in the context of NT AUTHORITY\SYSTEM.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-24331 ESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attacker to escalate privileges in the context of NT AUTHORITY\SYSTEM.
Fixes

Solution

No solution given by the vendor.


Workaround

The attack surface can also be eliminated by disabling the Enable advanced scanning via AMSI option in ESET products’ Advanced setup. However, ESET strongly recommends performing an upgrade to a fixed product version and only applying this workaround when the upgrade is not possible for an important reason.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: ESET

Published:

Updated: 2024-09-16T23:02:00.516Z

Reserved: 2021-08-02T00:00:00

Link: CVE-2021-37852

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-02-09T06:15:06.990

Modified: 2024-11-21T06:15:58.793

Link: CVE-2021-37852

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.