Executive brief
ESET Management Agent, which is used to manage and monitor security on Windows systems, contains a vulnerability that allows an attacker with Administrator privileges to escalate their access to the highest system level (SYSTEM account). An attacker could exploit this by manipulating temporary batch files used during command execution, potentially gaining complete control of the affected system. ESET has released patches to address this issue.
Technical details
The vulnerability is a local privilege escalation (LPE) caused by insecure handling of temporary batch files used during command execution from ESET PROTECT Web Console on Windows. Commands are stored in a predictable and writable location, allowing an attacker with Administrator privileges to modify these files before execution. When executed, the modified commands run under the SYSTEM account rather than Administrator context, resulting in privilege escalation. Local Administrator access is required to exploit this vulnerability. The fix is available in ESET Management Agent version 13.0.1400.0 and later, which implements improved security measures for file operations during command execution.
Affected products
- ESET Management Agent 12.5.2104.0 and earlier
Timeline
- 2026-02-06: disclosed
- 2026-02-06: patched: Fixed in ESET Management Agent version 13.0.1400.0