PT-2026-5395 · Eset · Eset Inspect Connector
CVE-2025-13176
·
Publicado
2026-01-30
·
Atualizado
2026-02-20
CVSS v4.0
8.4
Alta
| Vetor | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ESET Inspect Connector versions prior to 3.0.5765
Description
The ESET Inspect Connector is susceptible to a local privilege escalation. Planting a custom configuration file allows the loading of a malicious DLL. The
ElConnector.exe process, running with SYSTEM privileges, attempts to load an OpenSSL configuration file from a user-writable path. A low-privileged user can create this file, leading to the execution of arbitrary code with elevated privileges.Recommendations
Update ESET Inspect Connector to version 3.0.5765 or later.
Correção
LPE
Improper Privilege Management
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Eset Inspect Connector