Executive brief
A security vulnerability has been identified in ESET Inspect Connector, a tool used by organizations to monitor and respond to security threats on Windows computers. A person with limited access to a computer could exploit this flaw to gain full administrative control over that system. This could allow an attacker to bypass security controls, access sensitive data, or disrupt business operations.
Technical details
A local privilege escalation vulnerability exists in ESET Inspect Connector for Windows (versions 3.0.5775.0 and earlier) due to improper authentication and origin validation within an Advanced Local Procedure Call (ALPC) interface. An attacker with low-privileged local access can send specially crafted ALPC requests to the vulnerable process. Because the Inter-Process Communication (IPC) channel fails to verify the identity of the sender, the process accepts these messages, allowing the attacker to execute restricted functionality with the higher privileges of the ESET service. The issue is addressed in ESET Inspect Connector version 3.1.6017.0 and later.
Affected products
- ESET Inspect Connector 3.0.5775.0 and earlier
Timeline
- 2026-07-14: advisory: Initial advisory released by ESET
- 2026-07-16: disclosed: CVE published to NVD dataset