Description
ESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attacker to escalate privileges in the context of NT AUTHORITY\SYSTEM.
Published: 2022-02-09
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Workaround

The attack surface can also be eliminated by disabling the Enable advanced scanning via AMSI option in ESET products’ Advanced setup. However, ESET strongly recommends performing an upgrade to a fixed product version and only applying this workaround when the upgrade is not possible for an important reason.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-24331 ESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attacker to escalate privileges in the context of NT AUTHORITY\SYSTEM.
History

No history.

Subscriptions

Eset Endpoint Antivirus Endpoint Security File Security Internet Security Mail Security Nod32 Antivirus Security Server Security Smart Security
cve-icon MITRE

Status: PUBLISHED

Assigner: ESET

Published:

Updated: 2024-09-16T23:02:00.516Z

Reserved: 2021-08-02T00:00:00.000Z

Link: CVE-2021-37852

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-02-09T06:15:06.990

Modified: 2024-11-21T06:15:58.793

Link: CVE-2021-37852

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses