Executive brief
A security flaw in TXOne Networks' endpoint protection software could allow a user with administrative access to bypass file lockdown protections. This vulnerability specifically affects the system that validates removable media like USB drives, potentially allowing unauthorized files to be transferred onto a protected device. While the attacker needs high-level local access, this bypass undermines the integrity of the 'lockdown' security feature designed to prevent unauthorized data movement.
Technical details
An improper access control vulnerability exists in the Removable Media Validation function of TXOne SafePortAgent and StellarProtect. A local attacker with high privileges (Administrator) can bypass the file lockdown mechanism to transfer unauthorized files from removable media to the host system. The exploit requires the attacker to have pre-positioned unauthorized files on the media. The issue is resolved in SafePortAgent version 3.2.5024 and StellarProtect version 5.0.1083.
Affected products
- TXOne Networks SafePortAgent before 3.2.5024
- TXOne Networks StellarProtect 3.2.4011 to 5.0.1083
Timeline
- 2026-07-15: advisory: TXOne Networks published the security advisory.
- 2026-07-17: disclosed: CVE published to the NVD.