High severity7.8NVD Advisory· Published Feb 9, 2022· Updated Jun 17, 2026
CVE-2021-37852
CVE-2021-37852
Description
ESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attacker to escalate privileges in the context of NT AUTHORITY\SYSTEM.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
16- cpe:2.3:a:eset:endpoint_antivirus:*:*:*:*:*:windows:*:*Range: >=6.6.2046.0,<7.3.2055.0
- cpe:2.3:a:eset:endpoint_security:*:*:*:*:*:windows:*:*Range: >=6.6.2046.0,<7.3.2055.0
- cpe:2.3:a:eset:file_security:*:*:*:*:*:windows_server:*:*Range: >=7.0.12014.0,<=7.3.12006.0
- cpe:2.3:a:eset:internet_security:*:*:*:*:*:windows:*:*Range: >=10.0.337.1,<15.0.18.0
cpe:2.3:a:eset:mail_security:*:*:*:*:*:domino:*:*+ 1 more
- cpe:2.3:a:eset:mail_security:*:*:*:*:*:domino:*:*range: >=7.0.14008.0,<7.3.14003.0
- cpe:2.3:a:eset:mail_security:*:*:*:*:*:exchange_server:*:*range: >=7.0.10019,<7.3.10014.0
- cpe:2.3:a:eset:nod32_antivirus:*:*:*:*:*:windows:*:*Range: >=10.0.337.1,<=15.0.18.0
cpe:2.3:a:eset:server_security:*:*:*:*:azure:*:*:*+ 2 more
- cpe:2.3:a:eset:server_security:*:*:*:*:azure:*:*:*range: >=7.0.12016.1002,<=7.2.12004.1000
- cpe:2.3:a:eset:server_security:8.0.12003.0:*:*:*:*:windows_server:*:*
- cpe:2.3:a:eset:server_security:8.0.12003.1:*:*:*:*:windows_server:*:*
cpe:2.3:a:eset:smart_security:*:*:*:*:-:windows:*:*+ 1 more
- cpe:2.3:a:eset:smart_security:*:*:*:*:-:windows:*:*range: >=10.0.337.1,<=15.0.18.0
- cpe:2.3:a:eset:smart_security:*:*:*:*:premium:windows:*:*range: >=10.0.337.1,<=15.0.18.0
- Range: 7.0.14008.0
Patches
Vulnerability mechanics
References
2- support.eset.com/en/ca8223-local-privilege-escalation-vulnerability-fixed-in-eset-products-for-windowsnvdVendor Advisory
- www.zerodayinitiative.com/advisories/ZDI-22-148/nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.