PT-2026-5395 · Eset · Eset Inspect Connector

CVE-2025-13176

·

Publicado

2026-01-30

·

Atualizado

2026-02-20

CVSS v4.0

8.4

Alta

VetorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ESET Inspect Connector versions prior to 3.0.5765
Description The ESET Inspect Connector is susceptible to a local privilege escalation. Planting a custom configuration file allows the loading of a malicious DLL. The ElConnector.exe process, running with SYSTEM privileges, attempts to load an OpenSSL configuration file from a user-writable path. A low-privileged user can create this file, leading to the execution of arbitrary code with elevated privileges.
Recommendations Update ESET Inspect Connector to version 3.0.5765 or later.

Correção

LPE

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-13176

Produtos afetados

Eset Inspect Connector