ESET has recently published patches to fix a local privilege escalation vulnerability detected in all the clients of its Windows products that enables the threat actors to escalate privileges and execute arbitrary code.
The cybersecurity analysts at Zero Day Initiative (ZDI) on November 18, 2021, have identified and tracked vulnerability as “CVE-2021-37852,” which is marked as critical in terms of severity since it allows the threat actors to exploit the AMSI scanning function.
While after detecting and tracking this vulnerability, the ZDI team immediately reported this vulnerability to ESET.
Here below we have mentioned all the affected programs of ESET along with their respective versions:-
Here’s what ESET stated:-
“An attacker who can achieve SeImpersonatePrivilege rights will be able to exploit the AMSI scan function to elevate the privileges to NT AUTHORITY\SYSTEM.”
While the local Administrators group and the local device service accounts have access to SeImpersonatePrivilege by default. But, all these accounts already have relatively high privileges, and the impact of this error is very limited.
Moreover, ESET has already prepared a list of fixed products that are not vulnerable, and here they are mentioned below:-
In December 2021, a series of patches for this bug had already been released, and not only that even they have also released another batch of patches in January 2022 for all the older versions of Windows products.
Apart from this, by simply disabling the Enable advanced scanning via AMSI option from the settings, this issue can be fixed, and ESET has recommended users to use this workaround only if they aren’t able to install the available patches.
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates.
In a groundbreaking discovery on November 20, 2024, cybersecurity researchers Shubham Shah and a colleague…
A security flaw found in Android-based kiosk tablets at luxury hotels has exposed a grave…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued six Industrial Control Systems (ICS) advisories…
A sophisticated cyber campaign dubbed "J-magic" has been discovered targeting enterprise-grade Juniper routers with a…
In January, Netskope Threat Labs uncovered a sophisticated global malware campaign leveraging fake CAPTCHA pages…
In a recent technical investigation, researchers uncovered critical insights into the infrastructure linked to a…