CVE-2008-4451

ESET System Analyzer Tool 1.1.1.0 - Local Privilege Escalation via IOCTL Request

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-4451. PoCs published by NT Internals.

AI-analyzed exploit summary This exploit targets a vulnerability in the ESET SysInspector AntiStealth driver (esiasdrv.sys) by sending a malformed IOCTL request to trigger a denial-of-service condition. The code demonstrates interaction with the vulnerable driver via NtCreateFile and NtDeviceIoControlFile.

Description

The SysInspector AntiStealth driver (esiasdrv.sys) 3.0.65535.0 in ESET System Analyzer Tool 1.1.1.0 allows local users to execute arbitrary code via a certain METHOD_NEITHER IOCTL request to \Device\esiasdrv that overwrites a pointer.

Exploits (1)

exploitdb WORKING POC VERIFIED
by NT Internals · cdoswindows
https://www.exploit-db.com/exploits/6647

This exploit targets a vulnerability in the ESET SysInspector AntiStealth driver (esiasdrv.sys) by sending a malformed IOCTL request to trigger a denial-of-service condition. The code demonstrates interaction with the vulnerable driver via NtCreateFile and NtDeviceIoControlFile.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: ESET System Analyzer Tool 1.1.1.0 with Eset SysInspector AntiStealth driver 3.0.65535.0
No auth needed
Prerequisites: Access to the target system · Vulnerable ESET driver installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/45619
Exploit x_refsource_misc
http://www.ntinternals.org/
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/4353
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/31521
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6647

Scores

EPSS 0.0100
EPSS Percentile 58.0%

Details

CWE
CWE-264 CWE-94
Status published
Products (1)
eset_software/system_analyzer_tool 1.1.1.0
Published Oct 06, 2008
Tracked Since Feb 18, 2026