Permissions, Privileges, and Access Controls in Eset products - CVE-2021-37852
Published: February 3, 2022
Vulnerability identifier: #VU60263
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-37852
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions within the use of named pipes, which leads to security restrictions bypass and privilege escalation.
Affected software
NOD32
ESET Mail Security for Microsoft Exchange Server
ESET Mail Security for IBM Domino
ESET Security for Microsoft SharePoint Server
ESET File Security for Microsoft Windows Server
ESET Server Security for Microsoft Windows Server
ESET Internet Security
ESET Smart Security
ESET Endpoint Security for Windows
ESET Smart Security Premium
ESET Endpoint Antivirus for Windows
ESET Mail Security for Microsoft Exchange Server
ESET Mail Security for IBM Domino
ESET Security for Microsoft SharePoint Server
ESET File Security for Microsoft Windows Server
ESET Server Security for Microsoft Windows Server
ESET Internet Security
ESET Smart Security
ESET Endpoint Security for Windows
ESET Smart Security Premium
ESET Endpoint Antivirus for Windows
How to mitigate CVE-2021-37852
Install updates from vendor's website.
NOD32 - update to 15.0.19.0
ESET Mail Security for Microsoft Exchange Server - addressed in versions 7.3.10014.0, 8.0.10018.0
ESET Internet Security - update to 15.0.19.0
ESET Mail Security for IBM Domino - addressed in versions 7.3.14003.0, 8.0.14006.0
ESET Security for Microsoft SharePoint Server - addressed in versions 7.3.15002.0, 8.0.15006.0
ESET Smart Security - update to 15.0.19.0
ESET File Security for Microsoft Windows Server - update to 7.3.12008.0
ESET Endpoint Security for Windows - addressed in versions 7.3.2055.0, 7.3.2055.1, 8.0.2028.3, 8.0.2028.4, 8.0.2039.3, 8.0.2039.4, 8.0.2044.3, 8.0.2044.4, 8.1.2031.3, 8.1.2031.4, 8.1.2037.9, 8.1.2037.10, 9.0.2032.6, 9.0.2032.7
ESET Smart Security Premium - update to 15.0.19.0
ESET Endpoint Antivirus for Windows - addressed in versions 7.3.2055.0, 7.3.2055.1, 8.0.2028.3, 8.0.2028.4, 8.0.2039.3, 8.0.2039.4, 8.0.2044.3, 8.0.2044.4, 8.1.2031.3, 8.1.2031.4, 8.1.2037.9, 8.1.2037.10, 9.0.2032.6, 9.0.2032.7
ESET Server Security for Microsoft Windows Server - update to 8.0.12010.0
ESET Mail Security for Microsoft Exchange Server - addressed in versions 7.3.10014.0, 8.0.10018.0
ESET Internet Security - update to 15.0.19.0
ESET Mail Security for IBM Domino - addressed in versions 7.3.14003.0, 8.0.14006.0
ESET Security for Microsoft SharePoint Server - addressed in versions 7.3.15002.0, 8.0.15006.0
ESET Smart Security - update to 15.0.19.0
ESET File Security for Microsoft Windows Server - update to 7.3.12008.0
ESET Endpoint Security for Windows - addressed in versions 7.3.2055.0, 7.3.2055.1, 8.0.2028.3, 8.0.2028.4, 8.0.2039.3, 8.0.2039.4, 8.0.2044.3, 8.0.2044.4, 8.1.2031.3, 8.1.2031.4, 8.1.2037.9, 8.1.2037.10, 9.0.2032.6, 9.0.2032.7
ESET Smart Security Premium - update to 15.0.19.0
ESET Endpoint Antivirus for Windows - addressed in versions 7.3.2055.0, 7.3.2055.1, 8.0.2028.3, 8.0.2028.4, 8.0.2039.3, 8.0.2039.4, 8.0.2044.3, 8.0.2044.4, 8.1.2031.3, 8.1.2031.4, 8.1.2037.9, 8.1.2037.10, 9.0.2032.6, 9.0.2032.7
ESET Server Security for Microsoft Windows Server - update to 8.0.12010.0