🔥 この記事の詳細
2026-09-11 更新
B
今週中

ESETの複数の製品において、権限昇格が可能な脆弱性(CVE-2025-12858)が修正されました

脆弱性🌐 英語ソース
🖥️ 製品ESET
🔢 CVECVE-2025-12858
📅 2026-09-11📰 csirt_it
📌 一言でいうと
ESETの複数の製品において、権限昇格が可能な脆弱性(CVE-2025-12858)が修正されました。この脆弱性が悪用されると、攻撃者が対象システム上で特権を昇格させる可能性があります。影響を受ける製品にはESET AV RemoverやESET Endpoint Securityなどが含まれており、ベンダーは最新バージョンへの更新を推奨しています。
🔍該当判定
  • ESET AV Remover のバージョン 1.6.11.0 以前を利用している
  • ESET Endpoint Security または Endpoint Antivirus のバージョン 13.0.2044.0 以前を利用している
  • ESET PROTECT の Live Installer を 2026年8月6日以前に作成・利用している
  • ESET PROTECT On-Prem の Installer Agent または Security Application を 2026年9月3日以前に作成・利用している
上記いずれにも該当しない → 静観でOK
該当時の対応
ベンダーのセキュリティアドバイザリに従い、影響を受けるESET製品を最新バージョンにアップデートしてください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】ESET製品 CVE-2025-12858 対応について

お疲れさまです。ESET製品の脆弱性に関する情報共有です。

■ 概要
ESETの複数の製品において、権限昇格が可能な脆弱性(CVE-2025-12858)が報告されました。攻撃者がこの脆弱性を悪用した場合、システム上の権限を不正に昇格させる恐れがあります。

■ 影響範囲
- ESET AV Remover 1.6.11.0 以前
- ESET Endpoint Security (ESET AV Removerを含むインストーラー) 13.0.2044.0 以前
- ESET Endpoint Antivirus (ESET AV Removerを含むインストーラー) 13.0.2044.0 以前
- ESET PROTECT (Live Installer) 2026/08/06以前に生成されたもの
- ESET PROTECT On-Prem Installer Agent および Security Application 2026/09/03以前に生成されたもの

■ 対応手順
1. 利用中のESET製品のバージョンを確認してください。
2. ベンダーの公式セキュリティアドバイザリに基づき、最新バージョンへのアップデートを適用してください。

■ 参考情報
- https://support.eset.com/en/ca9000-eset-custo

対応優先度: 高
対応期限: 速やかに
Subject: [Security Advisory] ESET Products CVE-2025-12858 Mitigation

Dear IT/Security Team,

This is an information share regarding a vulnerability in ESET products.

■ Overview
An elevation of privilege vulnerability (CVE-2025-12858) has been identified in several ESET products. Successful exploitation could allow an attacker to gain elevated privileges on the affected system.

■ Scope
- ESET AV Remover 1.6.11.0 and earlier
- ESET Endpoint Security (installers containing ESET AV Remover) 13.0.2044.0 and earlier
- ESET Endpoint Antivirus (installers containing ESET AV Remover) 13.0.2044.0 and earlier
- ESET PROTECT (Live Installer) generated before 2026/08/06
- ESET PROTECT On-Prem Installer Agent and Security Application generated before 2026/09/03

■ Mitigation Steps
1. Verify the versions of ESET products currently deployed in the environment.
2. Update the affected products to the latest versions as per the vendor's security bulletin.

■ Reference
- https://support.eset.com/en/ca9000-eset-custo

Priority: High
Deadline: Immediate