CVE-2025-13818: Local privilege escalation in ESET Management Agent for Windows
Published Feb 6, 2026
·Updated
Local privilege escalation vulnerability via insecure temporary batch file execution in ESET Management Agent
Affected Software
2 affected components
ESET ESET Management Agent
ESET Management Agent<=12.5.2104.0
Event History
Feb 6, 2026
CVE Published
via MITRE·01:13 PM
Data Sourced
via MITRE·01:13 PM
DescriptionWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-13818?
CVE-2025-13818 is classified as a high severity local privilege escalation vulnerability.
2
How do I fix CVE-2025-13818?
To fix CVE-2025-13818, users should update to the latest version of ESET Management Agent provided by ESET.
3
What causes CVE-2025-13818?
CVE-2025-13818 is caused by insecure temporary batch file execution within the ESET Management Agent for Windows.
4
Who is affected by CVE-2025-13818?
Any organization using a vulnerable version of ESET Management Agent for Windows may be affected by CVE-2025-13818.
5
Can CVE-2025-13818 be exploited remotely?
CVE-2025-13818 requires local access to the system to exploit, making it a local privilege escalation vulnerability.