PT-2026-57573 · Secureage · Catchpulse
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SecureAge CatchPulse versions prior to 10.9.4
Description
A heap-based buffer overflow exists in the kernel driver component
saappctl.sys. A local attacker with low privileges can corrupt kernel memory via IOCTL (Input/Output Control) calls, which are requests sent from user-mode applications to kernel-mode drivers. This flaw allows the attacker to escalate privileges to SYSTEM level, potentially enabling them to disable Endpoint Detection and Response (EDR) systems, terminate security services, or install boot-level rootkits. Additionally, the signed driver could be used in Bring Your Own Vulnerable Driver (BYOVD) attacks to compromise other systems.Recommendations
Update to version 10.9.4.
Add the vulnerable driver
saappctl.sys to the Windows Defender Application Control (WDAC) blocklist.Exploit
Fix
Buffer Overflow
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Catchpulse