Executive brief
SecureAge CatchPulse, an endpoint security and antivirus solution, contains a vulnerability in its kernel driver. A person with physical or local login access to a computer could exploit this flaw to view sensitive information that should normally be protected. While the risk is rated as low, an exploit has been publicly released, and the vendor has not yet provided a fix.
Technical details
An information disclosure vulnerability exists in the IOCTL Handler of the saappctl.sys driver in SecureAge CatchPulse versions up to 10.9.1. The flaw is categorized under CWE-200 (Exposure of Sensitive Information) and CWE-284 (Improper Access Control). A local attacker with low privileges can send specifically crafted IOCTL requests to the driver to leak sensitive system information. Although the vendor was notified, no patch has been released as of the publication date. A public exploit has been disclosed.
Affected products
- SecureAge CatchPulse up to 10.9.1
Timeline
- 2026-06-07: advisory: NVD and VulDB published the vulnerability details.
- 2026-06-07: disclosed: Public exploit has been disclosed.