CVE-2025-14491
7.8RealDefense · SUPERAntiSpyware
A local privilege escalation vulnerability in the SAS Core Service of RealDefense SUPERAntiSpyware allows local attackers to execute arbitrary code with SYSTEM-level privileges.
Executive summary
A critical local privilege escalation vulnerability in RealDefense SUPERAntiSpyware permits low-privileged local attackers to gain full SYSTEM access to the host machine.
Vulnerability
The vulnerability exists within the SAS Core Service due to an exposed dangerous function. An attacker who has already achieved low-privileged code execution on the local system can exploit this function to escalate privileges to the SYSTEM context.
Business impact
This vulnerability carries a CVSS score of 7.8, indicating a high level of severity. By gaining SYSTEM-level access, an attacker can bypass all local security controls, install persistent backdoors, steal sensitive data, or disable security software, resulting in a total compromise of the affected host.
Remediation
Immediate Action: Contact the vendor for the latest security updates and apply any available patches for the SAS Core Service immediately.
Proactive Monitoring: Monitor system logs for unauthorized attempts to access or restart the SAS Core Service and watch for the execution of unusual child processes spawned by the service.
Compensating Controls: Restrict local access to the affected system to trusted users only and implement endpoint detection and response (EDR) solutions to identify and block privilege escalation attempts at the kernel or service level.
Exploitation status
Public Exploit Available: No (Exploit status is unknown; no weaponized exploit or public proof-of-concept has been confirmed).
Analyst recommendation
Given the ability for a local attacker to achieve full system control, this vulnerability represents a significant risk to environment integrity. Administrators should prioritize identifying instances of the affected version and applying vendor-provided mitigations as soon as they become available to prevent lateral movement or total host takeover.