ZeroHour

CVE-2026-12858

moderate

Local Privilege Escalation in ESET AV Remover (standalone)

CVSS 4.0
8.5 high
EPSS
<1%p1
Published
()
Modified
AI analysis

CVE-2026-12858 is an improper privilege management flaw (CWE-269) in the standalone edition of ESET AV Remover, a free utility used to uninstall third-party antivirus products. An attacker with low-privilege local access can trigger it by sending a specially crafted RPC call to the tool while it runs with elevated privileges. Successful exploitation results in privilege escalation with high impact on the confidentiality, integrity and availability of the local system (CVSS 4.0 score 8.5), effectively giving the attacker full control of the affected machine. Only users who have downloaded or deployed the standalone AV Remover are affected; it is a standalone cleanup utility, not ESET's core endpoint protection product. There are no reports of exploitation in the wild, no known public proof-of-concept, and the issue is not listed in CISA's KEV catalog.

What to do: Check whether the standalone ESET AV Remover is present on endpoints (including copies downloaded by IT staff) and update to the latest build published in ESET's advisory, since exact fixed version numbers are not included in the available data. Because the attack requires local low-privileged access, prioritize multi-user or shared machines and consider removing the utility after one-time use. Monitor ESET's advisory for updated versions and remediation details.

Affected
ESET AV Remover (standalone)
Estimated exposure
moderatelikely tens of thousands of installations worldwide (free on-demand standalone utility; no public install counts) — ESET AV Remover is a free cleanup tool downloaded mainly during antivirus migrations and removal tasks rather than being ESET's core protection product, so its active install base is plausibly in the tens of thousands, though ESET…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper Privilege Management vulnerability in ESET AV Remover (standalone) allows Privilege Escalation via especially crafted RPC.

Weakness
CWE-269
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.