ESET has recently published patches to fix a local privilege escalation vulnerability detected in all the clients of its Windows products that enables the threat actors to escalate privileges and execute arbitrary code.
The cybersecurity analysts at Zero Day Initiative (ZDI) on November 18, 2021, have identified and tracked vulnerability as “CVE-2021-37852,” which is marked as critical in terms of severity since it allows the threat actors to exploit the AMSI scanning function.
While after detecting and tracking this vulnerability, the ZDI team immediately reported this vulnerability to ESET.
Here below we have mentioned all the affected programs of ESET along with their respective versions:-
Here’s what ESET stated:-
“An attacker who can achieve SeImpersonatePrivilege rights will be able to exploit the AMSI scan function to elevate the privileges to NT AUTHORITY\SYSTEM.”
While the local Administrators group and the local device service accounts have access to SeImpersonatePrivilege by default. But, all these accounts already have relatively high privileges, and the impact of this error is very limited.
Moreover, ESET has already prepared a list of fixed products that are not vulnerable, and here they are mentioned below:-
In December 2021, a series of patches for this bug had already been released, and not only that even they have also released another batch of patches in January 2022 for all the older versions of Windows products.
Apart from this, by simply disabling the Enable advanced scanning via AMSI option from the settings, this issue can be fixed, and ESET has recommended users to use this workaround only if they aren’t able to install the available patches.
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates.
Hackers have reportedly infiltrated and extracted a vast 82 GB of sensitive data from the Indonesian…
IBM has issued a security bulletin warning of two vulnerabilities in its AIX operating system…
The Apache Software Foundation has issued a security alert regarding a critical vulnerability in Apache…
The Chinese National Internet Emergency Center (CNIE) has revealed two significant cases of cyber espionage…
A critical command injection vulnerability in the popular systeminformation npm package has recently been disclosed, exposing millions…
Researchers discovered a malware campaign targeting the npm ecosystem, distributing the Skuld info stealer through…