CVE-2021-37852

ESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attacker to escalate privileges in the context of NT AUTHORITY\SYSTEM.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:eset:endpoint_antivirus:*:*:*:*:*:windows:*:*
cpe:2.3:a:eset:endpoint_antivirus:*:*:*:*:*:windows:*:*
cpe:2.3:a:eset:endpoint_antivirus:*:*:*:*:*:windows:*:*
cpe:2.3:a:eset:endpoint_antivirus:*:*:*:*:*:windows:*:*
cpe:2.3:a:eset:endpoint_security:*:*:*:*:*:windows:*:*
cpe:2.3:a:eset:endpoint_security:*:*:*:*:*:windows:*:*
cpe:2.3:a:eset:endpoint_security:*:*:*:*:*:windows:*:*
cpe:2.3:a:eset:endpoint_security:*:*:*:*:*:windows:*:*
cpe:2.3:a:eset:file_security:*:*:*:*:*:windows_server:*:*
cpe:2.3:a:eset:internet_security:*:*:*:*:*:windows:*:*
cpe:2.3:a:eset:mail_security:*:*:*:*:*:exchange_server:*:*
cpe:2.3:a:eset:mail_security:*:*:*:*:*:domino:*:*
cpe:2.3:a:eset:mail_security:*:*:*:*:*:domino:*:*
cpe:2.3:a:eset:mail_security:*:*:*:*:*:exchange_server:*:*
cpe:2.3:a:eset:nod32_antivirus:*:*:*:*:*:windows:*:*
cpe:2.3:a:eset:security:*:*:*:*:*:sharepoint:*:*
cpe:2.3:a:eset:server_security:*:*:*:*:azure:*:*:*
cpe:2.3:a:eset:server_security:8.0.12003.0:*:*:*:*:windows_server:*:*
cpe:2.3:a:eset:server_security:8.0.12003.1:*:*:*:*:windows_server:*:*
cpe:2.3:a:eset:smart_security:*:*:*:*:-:windows:*:*
cpe:2.3:a:eset:smart_security:*:*:*:*:premium:windows:*:*

History

21 Nov 2024, 06:15

Type Values Removed Values Added
References () https://support.eset.com/en/ca8223-local-privilege-escalation-vulnerability-fixed-in-eset-products-for-windows - Vendor Advisory () https://support.eset.com/en/ca8223-local-privilege-escalation-vulnerability-fixed-in-eset-products-for-windows - Vendor Advisory
References () https://www.zerodayinitiative.com/advisories/ZDI-22-148/ - Third Party Advisory, VDB Entry () https://www.zerodayinitiative.com/advisories/ZDI-22-148/ - Third Party Advisory, VDB Entry

Information

Published : 2022-02-09 06:15

Updated : 2024-11-21 06:15


NVD link : CVE-2021-37852

Mitre link : CVE-2021-37852

CVE.ORG link : CVE-2021-37852


JSON object : View

Products Affected

eset

  • endpoint_security
  • internet_security
  • smart_security
  • file_security
  • server_security
  • nod32_antivirus
  • mail_security
  • endpoint_antivirus
  • security
CWE
CWE-269

Improper Privilege Management