[CA9000] ESET Customer Advisory: Local privilege escalation vulnerability in ESET AV Remover fixed

ESET Customer Advisory 2026-0016
September 9, 2026
Severity: High

Summary

ESET received a report of a local privilege escalation vulnerability in its ESET AV Remover tool by Khalid Matar Alharthi. The vulnerability was caused by missing authentication in an RPC interface. ESET mitigated this by preparing a fixed version of the affected tool.

Details

On systems with the affected ESET tool (or an installer bundled with the tool) present and running, an attacker could send a specially crafted Remote Procedure Call (RPC) request to the interface of the tool’s helper executable.

Without proper authentication or origin validation in place, this request would be accepted and processed, enabling the attacker to load an arbitrary malicious dynamic-link library (DLL). This would then result in the malicious code being run with SYSTEM permissions, achieving privilege escalation.

NOTE: The affected ESET AV Remover tool needs to be actively running for the attack to be viable. Past use of the affected tool or installer bundle does not present a current risk regarding this vulnerability. Additionally, the attacker would need to have previously obtained administrator rights to execute the attack, as the tool requires elevation to be run.

The reserved CVE ID for this vulnerability is CVE-2026-12858, the CVSS v4.0 score is 8.5, with the following vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N.

To the best of our knowledge, no exploits exist in the wild that target this vulnerability.

Solution

ESET prepared fixed builds of the affected tool and the installers it is bundled with, and recommends using these from now on. The fixed builds are available to download from www.eset.com or via the ESET Repository.

  • ESET AV Remover (standalone) 1.6.17.0 and later
  • Installers (.exe) containing ESET AV Remover:

    • ESET Endpoint Security and ESET Endpoint Antivirus 13.0.2058.0 and later, as well as any future releases from the 12.1 and earlier version families
    • Live installers generated in ESET PROTECT after August 6, 2026
    • Agent and security application installers generated in ESET PROTECT On-prem after September 3, 2026

Affected applications

  • ESET AV Remover (standalone) 1.6.11.0 and earlier
  • Installers (.exe) containing ESET AV Remover (launched in offline environments):

    • ESET Endpoint Security and ESET Endpoint Antivirus 13.0.2044.0 and earlier
    • Live installers generated in ESET PROTECT on or before August 6, 2026
    • Agent and security application installers generated in ESET PROTECT On-prem on or before September 3, 2026

IMPORTANT: ESET security applications (ESET Endpoint Security and ESET Endpoint Antivirus) themselves are not affected and using the versions listed above does not present a risk regarding this vulnerability. The vulnerability is only present in the installer bundled with ESET AV Remover and can only be exploited while the installer is running. Additionally, ESET has released a fixed version of the ESET AV Remover component to its infrastructure, so any installer (even one listed as affected) will download the patched ESET AV Remover component upon its launch and run that instead, provided there is internet connectivity.

NOTE: ESET application versions that no longer receive hotfixes according to the End of Life policy may not be listed.

Feedback & Support

If you have feedback or questions about this issue, contact us using the ESET Security Forum, or via local ESET Technical Support.

Acknowledgement

ESET values the principles of coordinated disclosure within the security industry and would like to express our thanks to Khalid Matar Alharthi.

Version log

Version 1.0 (September 9, 2026): Initial version of this document