Impact
ESET Inspect Connector contains a flaw where an ALPC channel does not perform proper authentication. The vendor description does not expand the acronym ALPC; it is understood to refer to a Windows inter-process communication channel, an inference not stated explicitly. This weakness enables a local attacker to impersonate a privileged process and execute actions with elevated rights. The vulnerability aligns with CWE‑269, which describes authentication bypass through privilege escalation, and can allow attackers to gain system‑level access on the affected host.
Affected Systems
The issue affects the ESET Inspect Connector component provided by ESET, spol. s.r.o. No specific version ranges are listed in the entry, so any installation of this product that has not been updated according to the vendor advisory is potentially vulnerable.
Risk and Exploitability
The CVSS base score is 8.5, indicating a high severity for local privilege escalation. However, the EPSS score is less than 1%, so the likelihood of exploitation in the wild is currently very low. The vulnerability is not listed in the to the affected machine and relies on the ability to interact with the ALPC IPC channel, making remote exploitation unlikely without prior local compromise.
OpenCVE Enrichment