Description
Improper Privilege Management vulnerability in ESET AV Remover (standalone) allows Privilege Escalation via especially crafted RPC.
Published: 2026-09-09
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

This vulnerability is an improper privilege management flaw in the standalone ESET AV Remover. It allows an attacker who can craft a special RPC message to elevate their privileges within the system. The flaw directly maps to CWE-269, indicating that the application does not properly enforce identity and privilege checks when handling RPC calls.

Affected Systems

ESET spol. s.r.o. ESET AV Remover (standalone). No specific affected versions were disclosed, so all installations of the product that rely on the affected RPC handling mechanism are potentially impacted.

Risk and Exploitability

The CVSS score of 8.5 classifies this flaw as high severity. Though the EPSS score is not provided, the lack of an EPSS value does not diminish the risk; the flaw remains a serious local privilege escalation vulnerability. It is not listed in the CISA KEV catalog. The attack requires local access to the ESET AV Remover service and the ability to send a crafted RPC request, meaning that an attacker who can run code on the machine or bypass local login restrictions could exploit it to gain higher privileges.

Generated by OpenCVE AI on September 9, 2026 at 10:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest ESET AV Remover update or patch released by ESET (see the official advisory).
  • Disable or restrict RPC access to the ESET AV Remover service if it is not required for normal operations.
  • Ensure that only authorized users have local administrative privileges, reducing the opportunity for privilege escalation.

Generated by OpenCVE AI on September 9, 2026 at 10:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Eset
Eset eset Av Remover (standalone)
Vendors & Products Eset
Eset eset Av Remover (standalone)

Wed, 09 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description Improper Privilege Management vulnerability in ESET AV Remover (standalone) allows Privilege Escalation via especially crafted RPC.
Title Local privilege escalation vulnerability in ESET AV Remover
Weaknesses CWE-269
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Eset Eset Av Remover (standalone)
cve-icon MITRE

Status: PUBLISHED

Assigner: ESET

Published:

Updated: 2026-09-09T12:57:45.394Z

Reserved: 2026-06-22T06:56:40.919Z

Link: CVE-2026-12858

cve-icon Vulnrichment

Updated: 2026-09-09T12:57:36.920Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T09:17:10.320

Modified: 2026-09-09T15:39:13.607

Link: CVE-2026-12858

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:01:54Z

Weaknesses
  • CWE-269

    Improper Privilege Management