Skip to content
ESETCVE-2026-12858

ESET AV Remover (standalone): privilege escalation

High8.5CVE-2026-12858 · Published Sep 9, 2026

Improper Privilege Management vulnerability in ESET AV Remover (standalone) allows Privilege Escalation via especially crafted RPC.

ESET advisory

Affected versions

PackageAffectedFixed in
ESET AV Remover (standalone)
Product
<= 1.6.11.0No fix yet
Details and references
CVSS 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-269

More ESET advisories

All ESET
Advisory
ESET Cyber Security for macOS: privilege escalation
High8.5Jul 24
ESET Cyber Security for macOS: privilege escalation
High8.5Jul 24
ESET Inspect Connector: privilege escalation
High8.5Jul 16
ESET Endpoint Antivirus for Linux: use after free
Medium6.7Jul 16

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.