

ESET Mail Security for Microsoft Exchange Server from version 9 to 6.0.ESET Mail Security for IBM Domino from version 8.0 to 4.0.ESET Security for Microsoft SharePoint Server from version 8.0 to 4.0.ESET Server Security for Microsoft Azure from version 6.1002 to 4.1000.ESET Server Security for Microsoft Windows Server 3.0 and 3.1, ESET File Security for Microsoft Windows Server from version 4.0 to 6.0.ESET Endpoint Antivirus for Windows and ESET Endpoint Security for Windows from version.ESET NOD32 Antivirus, ESET Internet Security, ESET Smart Security, and ESET Smart Security Premium from version 10.0.337.1 to 15.0.18.0.FINDING CREDIT: Michael DePlante of Trend Micro’s Zero Day Initiative.Īll of ESET's impacted applications, along with their corresponding versions, are listed below:.DISCLOSURE TIMELINE: – Vulnerability reported to vendor & – Coordinated public release of advisory.DESCRIPTION: ESET Endpoint Antivirus Unnecessary Privileges Local Privilege Escalation Vulnerability.On November 18, 2021, cybersecurity experts at Zero Day Initiative (ZDI) detected and documented a vulnerability as "CVE-2021-37852," which is characterised as severe in terms of severity since it allows threat actors to exploit the AMSI scanning function. ESET has just released updates to address a local privilege escalation vulnerability discovered in all of its windows clients, which allows threat actors to escalate privileges and execute arbitrary code.
