CVE-2026-12858: Local privilege escalation vulnerability in ESET AV Remover
Published Sep 9, 2026
·Updated
Improper Privilege Management vulnerability in ESET AV Remover (standalone) allows Privilege Escalation via especially crafted RPC.
Affected Software
1 affected component
ESET ESET AV Remover (standalone)
Event History
Sep 9, 2026
CVE Published
via MITRE·08:29 AM
Data Sourced
via MITRE·08:29 AM
DescriptionWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The issue is described as a local privilege escalation vulnerability, so exploitation requires local access to the affected system. The attacker uses specially crafted RPC requests to elevate privileges.
2
Which deployment is affected?
The affected software is ESET AV Remover in its standalone deployment. The provided information does not identify other ESET products or deployment modes as affected.