Executive brief
Absolute Security Secure Access is a client application used to provide secure remote connectivity for mobile workers. A vulnerability in how the software processes security certificates could allow a user who already has administrative access to the device to crash the connection client. While this results in a denial of service for that specific user, it requires high-level local permissions to execute.
Technical details
A heap-based buffer overflow exists in the certificate parsing function of Absolute Security (formerly NetMotion) Secure Access clients. The vulnerability is triggered when the client processes a specially crafted certificate. An attacker must have local access to the machine and possess administrator-level privileges to exploit this flaw. Successful exploitation results in a denial of service (DoS) by crashing the Secure Access client. The issue is resolved in client versions 14.55 and later.
Affected products
- Absolute Security (formerly NetMotion) Secure Access prior to 14.55
Timeline
- 2026-07-15: advisory
- 2026-07-15: disclosed