Executive brief
SecureAge CatchPulse, an endpoint security and antivirus solution, contains a vulnerability in its kernel-mode driver. A local attacker with basic user access could exploit this flaw to crash the system or potentially gain elevated administrative privileges. This could lead to a full compromise of the affected computer and the bypass of security protections.
Technical details
A heap-based buffer overflow vulnerability exists in the saappctl.sys driver component of SecureAge CatchPulse versions up to 10.9.3. The flaw is located within an unknown function in the driver library and can be triggered through specific manipulation of input. An attacker requires local access and low privileges (PR:L) to exploit this vulnerability. Successful exploitation can lead to arbitrary code execution in kernel mode, resulting in full system compromise (Complete Confidentiality, Integrity, and Availability impact). A public exploit has been disclosed.
Affected products
- SecureAge CatchPulse up to 10.9.3
Timeline
- 2026-07-12: advisory: NVD publication date
- 2026-07-12: disclosed: Public disclosure of the exploit