CVE-2025-14490
7.8RealDefense · SUPERAntiSpyware
A local privilege escalation vulnerability exists in the RealDefense SUPERAntiSpyware SAS Core Service due to an exposed dangerous function, allowing low-privileged code to execute as SYSTEM.
Executive summary
A critical local privilege escalation vulnerability in RealDefense SUPERAntiSpyware allows a low-privileged attacker to achieve arbitrary code execution with SYSTEM-level privileges.
Vulnerability
The flaw resides within the SAS Core Service, which exposes a dangerous function that can be leveraged by an attacker who already possesses the ability to execute low-privileged code on the host. This vulnerability allows the attacker to bypass standard security restrictions and execute arbitrary code in the context of the SYSTEM account.
Business impact
The ability for a local user to escalate privileges to SYSTEM status poses a severe threat to the confidentiality, integrity, and availability of the host system. With SYSTEM-level access, an attacker can disable security software, install persistent backdoors, or exfiltrate sensitive enterprise data. Given the CVSS score of 7.8, this flaw represents a high-risk entry point for lateral movement within a network environment.
Remediation
Immediate Action: Monitor official vendor channels for the release of a security patch and apply the update to version 10.0.1276 or newer immediately upon availability.
Proactive Monitoring: Review system logs for unauthorized attempts to interact with the SAS Core Service or unexpected process execution patterns originating from low-privileged user accounts.
Compensating Controls: Restrict local user permissions where possible to limit the ability of unauthorized code to execute, and employ Endpoint Detection and Response (EDR) solutions to monitor for privilege escalation attempts.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability presents a significant risk to system security by allowing full administrative compromise from a low-privileged starting point. Organizations should treat this as a high priority for patching once RealDefense issues a resolution, as the ability to gain SYSTEM-level access is a primary objective for attackers seeking to establish long-term persistence on a compromised host.