Junglewise Threat Intelligence

CVE-2026-12858: ESET AV Remover privilege escalation in RPC interface

CVE-2026-12858 · Severity: info · CVSS 8.5 · Published 2026-09-09

Vendors: Eset.

Executive brief

ESET AV Remover is a standalone utility tool used to remove competing antivirus software from systems. A local privilege escalation vulnerability in its RPC interface allows an authenticated administrator to load arbitrary malicious code that runs with SYSTEM permissions. An attacker with admin credentials can exploit this by sending a specially crafted RPC request while the tool is running, completely compromising the system.

Technical details

This is an improper privilege management and missing authentication vulnerability in the RPC interface of ESET AV Remover's helper executable. The root cause is the absence of proper authentication and origin validation on RPC requests. An attacker with local administrator privileges can send a specially crafted RPC request to load an arbitrary DLL, which then executes with SYSTEM-level permissions. The attack requires the tool to be actively running and the attacker to already possess administrator rights. ESET has released fixed versions: ESET AV Remover 1.6.17.0 and later for the standalone tool, and updated versions of ESET Endpoint Security/Antivirus (13.0.2058.0 and later) for bundled installers.

Affected products

  • ESET AV Remover 1.6.11.0 and earlier
  • ESET Endpoint Security 13.0.2044.0 and earlier (when bundled with affected AV Remover)
  • ESET Endpoint Antivirus 13.0.2044.0 and earlier (when bundled with affected AV Remover)

Timeline

  • 2026-09-09: disclosed: ESET Customer Advisory CA9000 published
  • 2026-09-09: patched: ESET AV Remover 1.6.17.0 and later released; ESET Endpoint Security/Antivirus 13.0.2058.0 and later available

References