Secureage · Catchpulse · CVE-2026-15506
**Name of the Vulnerable Software and Affected Versions**
SecureAge CatchPulse versions prior to 10.9.4
**Description**
A heap-based buffer overflow exists in the kernel driver component `saappctl.sys`. A local attacker with low privileges can corrupt kernel memory via IOCTL (Input/Output Control) calls, which are requests sent from user-mode applications to kernel-mode drivers. This flaw allows the attacker to escalate privileges to SYSTEM level, potentially enabling them to disable Endpoint Detection and Response (EDR) systems, terminate security services, or install boot-level rootkits. Additionally, the signed driver could be used in Bring Your Own Vulnerable Driver (BYOVD) attacks to compromise other systems.
**Recommendations**
Update to version 10.9.4.
Add the vulnerable driver `saappctl.sys` to the Windows Defender Application Control (WDAC) blocklist.