CVE-2021-37852

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
09/02/2022
Last modified:
12/07/2022

Description

ESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attacker to escalate privileges in the context of NT AUTHORITY\SYSTEM.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:eset:endpoint_antivirus:*:*:*:*:*:windows:*:* 6.6.2046.0 (including) 7.3.2055.0 (excluding)
cpe:2.3:a:eset:endpoint_antivirus:*:*:*:*:*:windows:*:* 8.0 (including) 8.0.2028.3 (excluding)
cpe:2.3:a:eset:endpoint_antivirus:*:*:*:*:*:windows:*:* 8.1 (including) 8.1.2031.4 (excluding)
cpe:2.3:a:eset:endpoint_antivirus:*:*:*:*:*:windows:*:* 9.0 (including) 9.0.2032.6 (excluding)
cpe:2.3:a:eset:endpoint_security:*:*:*:*:*:windows:*:* 6.6.2046.0 (including) 7.3.2055.0 (excluding)
cpe:2.3:a:eset:endpoint_security:*:*:*:*:*:windows:*:* 8.0 (including) 8.0.2028.3 (excluding)
cpe:2.3:a:eset:endpoint_security:*:*:*:*:*:windows:*:* 8.1 (including) 8.1.2031.4 (excluding)
cpe:2.3:a:eset:endpoint_security:*:*:*:*:*:windows:*:* 9.0 (including) 9.0.2032.6 (excluding)
cpe:2.3:a:eset:file_security:*:*:*:*:*:windows_server:*:* 7.0.12014.0 (including) 7.3.12006.0 (including)
cpe:2.3:a:eset:internet_security:*:*:*:*:*:windows:*:* 10.0.337.1 (including) 15.0.18.0 (excluding)
cpe:2.3:a:eset:mail_security:*:*:*:*:*:exchange_server:*:* 7.0.10019 (including) 7.3.10014.0 (excluding)
cpe:2.3:a:eset:mail_security:*:*:*:*:*:domino:*:* 7.0.14008.0 (including) 7.3.14003.0 (excluding)
cpe:2.3:a:eset:mail_security:*:*:*:*:*:domino:*:* 8.0 (including) 8.0.14006.0 (excluding)
cpe:2.3:a:eset:mail_security:*:*:*:*:*:exchange_server:*:* 8.0.10012.0 (including) 8.0.10018.0 (excluding)
cpe:2.3:a:eset:nod32_antivirus:*:*:*:*:*:windows:*:* 10.0.337.1 (including) 15.0.18.0 (including)