PT-2026-5395 · Eset · Eset Inspect Connector
Published
2026-01-30
·
Updated
2026-02-20
·
CVE-2025-13176
CVSS v4.0
8.4
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ESET Inspect Connector versions prior to 3.0.5765
Description
The ESET Inspect Connector is susceptible to a local privilege escalation. Planting a custom configuration file allows the loading of a malicious DLL. The
ElConnector.exe process, running with SYSTEM privileges, attempts to load an OpenSSL configuration file from a user-writable path. A low-privileged user can create this file, leading to the execution of arbitrary code with elevated privileges.Recommendations
Update ESET Inspect Connector to version 3.0.5765 or later.
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Eset Inspect Connector