PT-2026-57573 · Secureage · Catchpulse

·

CVE-2026-15506

·

Published

2026-07-12

·

Updated

2026-07-13

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SecureAge CatchPulse versions prior to 10.9.4
Description A heap-based buffer overflow exists in the kernel driver component saappctl.sys. A local attacker with low privileges can corrupt kernel memory via IOCTL (Input/Output Control) calls, which are requests sent from user-mode applications to kernel-mode drivers. This flaw allows the attacker to escalate privileges to SYSTEM level, potentially enabling them to disable Endpoint Detection and Response (EDR) systems, terminate security services, or install boot-level rootkits. Additionally, the signed driver could be used in Bring Your Own Vulnerable Driver (BYOVD) attacks to compromise other systems.
Recommendations Update to version 10.9.4. Add the vulnerable driver saappctl.sys to the Windows Defender Application Control (WDAC) blocklist.

Exploit

Fix

Buffer Overflow

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15506

Affected Products

Catchpulse