Impact
This vulnerability is an improper privilege management flaw in the standalone ESET AV Remover. It allows an attacker who can craft a special RPC message to elevate their privileges within the system. The flaw directly maps to CWE-269, indicating that the application does not properly enforce identity and privilege checks when handling RPC calls.
Affected Systems
ESET spol. s.r.o. ESET AV Remover (standalone). No specific affected versions were disclosed, so all installations of the product that rely on the affected RPC handling mechanism are potentially impacted.
Risk and Exploitability
The CVSS score of 8.5 classifies this flaw as high severity. Though the EPSS score is not provided, the lack of an EPSS value does not diminish the risk; the flaw remains a serious local privilege escalation vulnerability. It is not listed in the CISA KEV catalog. The attack requires local access to the ESET AV Remover service and the ability to send a crafted RPC request, meaning that an attacker who can run code on the machine or bypass local login restrictions could exploit it to gain higher privileges.
OpenCVE Enrichment