The Personal Firewall driver (aka epfw.sys) 3.0.672.0 and earlier in ESET Smart Security 3.0.672 and earlier allows local users to gain privileges via a crafted IRP in a certain METHOD_NEITHER IOCTL request to \Device\Epfw that overwrites portions of memory.
AV:L/AC:L/Au:N/C:C/I:C/A:C
This vulnerability has a 0.80% probability of being exploited in the next 30 days, ranking higher than 55% of all scored CVEs.