CVE-2025-13176General

MEDIUMCVSS 8.4 · HIGH

Exploit discussion active in current signal (4 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Planting a custom configuration file in ESET Inspect Connector allow load a malicious DLL.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

RISING

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 9 mentions across 6 observed days
  • Momentum state: rising

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • General: 4 classified signals
  • Disclosure: 2 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-02-19)
  • 9 total mentions across 6 days

Deep dive

Activity timeline9 mentions / 6d
01234Mentions · 2026-01-30: 1Mentions · 2026-02-02: 1Mentions · 2026-02-05: 1Mentions · 2026-02-17: 1Mentions · 2026-02-18: 1Mentions · 2026-02-19: 4PoC Mentioned / Linked · 2026-02-17: 1PoC Mentioned / Linked · 2026-02-19: 1Exploit Tool / Code · 2026-02-19: 1Patch / Workaround · 2026-02-02: 1Technical Details · 2026-01-30: 1Technical Details · 2026-02-02: 1Technical Details · 2026-02-17: 1Technical Details · 2026-02-18: 1Technical Details · 2026-02-19: 201-3002-0202-0502-1702-1802-19
Signal classification5 categories
General
444.4%
Disclosure
222.2%
Patch
111.1%
PoC
111.1%
Exploit
111.1%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-01-301
Disclosure1
2026-02-021
Patch1
2026-02-051
General1
2026-02-171
PoC1
2026-02-181
Disclosure1
2026-02-194
Exploit1General3
Full discourse9 posts
  • Co11ateral@co11ateral
    Disclosure

    CVE-2025-13176: Local Privilege Escalation in ESET Inspect EDR LPE vulnerability in the ESET Inspect Connector for Windows (versions prior to 3.0.5765) due to the ElConnector.exe process (running as SYSTEM) attempting to load an OpenSSL configuration file from a non-existent path that can be created by a low-privileged user https://labs.infoguard.ch/advisories/cve-2025-13176_eset-inspect_edr_local-privilege-escalation/ #dfir #incidentresponse #Pentesting #ThreatHunting #blueteam

    Post summary

    ESET Inspect Connector for Windows versions before 3.0.5765 suffers a local privilege escalation flaw where a low‑privileged user can create a non‑existent OpenSSL configuration path that is loaded by the SYSTEM‑running ElConnector.exe, allowing escalation of privileges.

    1291110437.5K
    1.3K followersView on X
  • InfoGuard Labs@InfoGuard_Labs
    PoC

    Need a SYSTEM shell? Just ask your EDR! CVE-2025-13176: ESET Inspect Connector looks for an OpenSSL config in a user-writable path. It’s an easy LPE that loads your payload directly into the EDR process. by @p0w1_ https://labs.infoguard.ch/advisories/cve-2025-13176_eset-inspect_edr_local-privilege-escalation/

    Post summary

    The advisory highlights an easy local privilege escalation in ESET Inspect Connector that injects a payload into the EDR process via a user‑writable OpenSSL config, with a PoC link provided.

    129099558.2K
    187 followersView on X
  • Autumn Good@autumn_good_35
    Patch

    CVE-2025-13176 [CA8910] ESET Customer Advisory: Local privilege escalation vulnerability fixed in ESET Inspect Connector for Windows https://support.eset.com/en/ca8910-eset-customer-advisory-local-privilege-escalation-vulnerability-fixed-in-eset-inspect-connector-for-windows

    Post summary

    ESET’s advisory confirms that CVE‑2025‑13176, a local privilege escalation vulnerability in Inspect Connector for Windows, has been fixed, with no PoC, exploit code, or active exploitation reported.

    10011898
    6.7K followersView on X
  • Mr. OS@ksg93rd
    Exploit

    #exploit 1⃣ CVE-2026-25903: https://seclists.org/oss-sec/2026/q1/166 Apache NiFi: Missing Authorization of Restricted Permissions for Component Updates 2⃣ CVE-2025-13176: https://labs.infoguard.ch/advisories/cve-2025-13176_eset-inspect_edr_local-privilege-escalation LPE in ESET Inspect EDR 3⃣ From BRICKSTORM to GRIMBOLT: https://cloud.google.com/blog/topics/threat-intelligence/unc6201-exploiting-dell-recoverpoint-zero-day UNC6201 Exploiting a Dell RecoverPoint for Virtual Machines 0-Day 4⃣ CVE-2026-0770: https://github.com/affix/CVE-2026-0770-PoC Langflow Remote Code Execution 5⃣ JWT Authentication Bypass in OpenID Connect Authenticator for Tomcat https://insinuator.net/2026/02/jwt-authentication-bypass-in-openid-connect-authenticator-for-tomcat/ 6⃣ CVE-2026-2329: https://www.rapid7.com/blog/post/ve-cve-2026-2329-critical-unauthenticated-stack-buffer-overflow-in-grandstream-gxp1600-voip-phones-fixed/ Critical Unauthenticated Stack Buffer Overflow in Grandstream GXP1600 VoIP Phones

    Post summary

    The post catalogs several CVEs, provides links to PoC or exploit code, offers technical vulnerability details, but does not report active exploitation or patches.

    10000217
    3.0K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2023-6318 2 - CVE-2026-23101 3 - CVE-2025-13176 4 - CVE-2026-20817 5 - CVE-2026-22769 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post lists five trending CVEs but provides no additional information about exploitation, patches, or technical details.

    00010157
    1.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-13176 Planting a custom configuration file in ESET Inspect Connector allow load a malicious DLL. https://www.cve.org/CVERecord?id=CVE-2025-13176

    Post summary

    The text announces CVE‑2025‑13176, noting that ESET Inspect Connector can load a malicious DLL via a custom configuration file, but provides no evidence of active exploitation, PoC, or patch.

    00010320
    56.5K followersView on X
  • Yo-Yo With Elon Balls@kuulte
    General

    CVE-2025-13176

    Post summary

    The text contains only the CVE identifier with no further detail.

    0000049
    161 followersView on X
  • Autumn Good@autumn_good_35
    General

    『because the code execution occurs within the context of the EDR agent itself, this technique can be used to bypass security protections and telemetry,』😲 CVE-2025-13176: Local Privilege Escalation in ESET Inspect EDR - InfoGuard Labs https://labs.infoguard.ch/advisories/cve-2025-13176_eset-inspect_edr_local-privilege-escalation/

    Post summary

    InfoGuard Labs reports CVE‑2025‑13176 as a local privilege escalation flaw in ESET Inspect EDR, enabling code execution inside the agent to bypass security protections and telemetry, with no evidence of exploitation or patch details provided.

    00000310
    6.7K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidad en productos ESET ❗ CVE-2025-13176 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-eset/ https://t.co/KDKxR9eZYe

    Post summary

    Short notice about CVE-2025-13176 affecting ESET products, directing readers to a link for further information.

    00000130
    6.6K followersView on X

Explore more