Vulnerability Description
ESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attacker to escalate privileges in the context of NT AUTHORITY\SYSTEM.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Eset | Endpoint Antivirus | >= 6.6.2046.0, < 7.3.2055.0 |
| Eset | Endpoint Security | >= 6.6.2046.0, < 7.3.2055.0 |
| Eset | File Security | >= 7.0.12014.0, <= 7.3.12006.0 |
| Eset | Internet Security | >= 10.0.337.1, < 15.0.18.0 |
| Eset | Mail Security | >= 7.0.10019, < 7.3.10014.0 |
| Eset | Nod32 Antivirus | >= 10.0.337.1, <= 15.0.18.0 |
| Eset | Security | >= 7.0.15008.0, <= 8.0.15004.0 |
| Eset | Server Security | >= 7.0.12016.1002, <= 7.2.12004.1000 |
| Eset | Smart Security | >= 10.0.337.1, <= 15.0.18.0 |
Related Weaknesses (CWE)
References
- https://support.eset.com/en/ca8223-local-privilege-escalation-vulnerability-fixeVendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-22-148/Third Party AdvisoryVDB Entry
- https://support.eset.com/en/ca8223-local-privilege-escalation-vulnerability-fixeVendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-22-148/Third Party AdvisoryVDB Entry
FAQ
What is CVE-2021-37852?
CVE-2021-37852 is a vulnerability with a CVSS score of 7.8 (HIGH). ESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attacker to escalate privileges in the context of NT AUTHORITY\SYSTEM.
How severe is CVE-2021-37852?
CVE-2021-37852 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-37852?
Check the references section above for vendor advisories and patch information. Affected products include: Eset Endpoint Antivirus, Eset Endpoint Security, Eset File Security, Eset Internet Security, Eset Mail Security.