# ESET AV Remover flaw allows privilege escalation

Published: 2026-09-09 · Severity: routine
Canonical: https://vorant.io/reports/557e1e8d-af99-5284-af4b-ee57d923f609/eset-av-remover-flaw-allows-privilege-escalation

> ANSSI advisory warns of a privilege escalation vulnerability in ESET AV Remover versions prior to 1.6.17.0, patched by the vendor.

ANSSI (CERT-FR) published an advisory describing a privilege escalation vulnerability affecting ESET AV Remover in versions prior to 1.6.17.0. The flaw, tracked as CVE-2026-12858, could allow a local attacker to elevate privileges on an affected system. ESET has released a security bulletin addressing the issue, and the advisory directs administrators to apply the vendor-supplied patch.

No evidence of active exploitation is mentioned in the advisory. This is a standard vendor patch notification requiring organizations running ESET AV Remover to update to version 1.6.17.0 or later to remediate the vulnerability.

## Mentioned in this report

- Vulnerabilities: CVE-2026-12858

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1143

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/557e1e8d-af99-5284-af4b-ee57d923f609/eset-av-remover-flaw-allows-privilege-escalation.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
