CVE-2026-12858
Deferred Deferred - Pending Action

Improper Privilege Management in ESET AV Remover

Vulnerability report for CVE-2026-12858, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: ESET

Description

Improper Privilege Management vulnerability in ESET AV Remover (standalone) allows Privilege Escalation via especially crafted RPC.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
eset av_remover *
eset av_remover to 1.6.17.0 (exc)
eset av_remover From 1.6.17.0 (inc)
eset endpoint_security From 13.0.2058.0 (inc)
eset endpoint_antivirus From 13.0.2058.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-12858 is a high-severity local privilege escalation vulnerability in ESET AV Remover. It occurs due to missing authentication in an RPC interface of the tool’s helper executable. An attacker with prior administrator rights could exploit this by sending a crafted RPC request to load a malicious DLL, executing code with SYSTEM privileges.

Detection Guidance

Check if ESET AV Remover is installed and running. Verify the version installed against the affected versions (1.6.11.0 or earlier). Use system tools to inspect running processes and RPC interfaces for suspicious activity.

Impact Analysis

If you have ESET AV Remover installed, an attacker with admin rights could exploit this to gain SYSTEM privileges on your system. This could allow them to take full control of your computer, install malware, or access sensitive data. The vulnerability only affects systems where the tool is actively running.

Compliance Impact

This vulnerability could potentially impact compliance with standards like GDPR and HIPAA by enabling unauthorized privilege escalation. An attacker gaining SYSTEM privileges could access or modify sensitive data, violating confidentiality and integrity requirements under these regulations. The lack of authentication in the RPC interface increases the risk of such breaches.

Mitigation Strategies

Update ESET AV Remover to version 1.6.17.0 or later. For ESET Endpoint Security and ESET Endpoint Antivirus, update to version 13.0.2058.0 or later. Remove or disable the affected tool if not needed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12858. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart