CVE-2025-14492

7.8

RealDefense · SUPERAntiSpyware

RealDefense SUPERAntiSpyware contains an exposed dangerous function in the SAS Core Service, allowing local, low-privileged attackers to escalate their privileges to SYSTEM level.

Executive summary

A high-severity local privilege escalation vulnerability in RealDefense SUPERAntiSpyware allows low-privileged attackers to gain full SYSTEM control over the host.

Vulnerability

The vulnerability exists within the SAS Core Service due to an exposed dangerous function. A local attacker with authenticated, low-privileged access can interact with this service to execute arbitrary code with SYSTEM privileges.

Business impact

This vulnerability carries a CVSS score of 7.8, reflecting its high potential for system compromise. By escalating to SYSTEM privileges, an attacker gains total control over the affected machine, which can lead to data exfiltration, the installation of persistent malware, and the complete bypass of local security controls.

Remediation

Immediate Action: As no specific patch version is currently identified in the enrichment data, users should restrict local system access to authorized personnel and monitor the SAS Core Service for unauthorized interactions.

Proactive Monitoring: Security teams should audit system logs for unexpected service calls or process spawning originating from the SAS Core Service.

Compensating Controls: Implement strict principle of least privilege policies for all local user accounts to ensure that attackers cannot obtain the initial low-privileged code execution required to trigger this flaw.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the severity of a local privilege escalation, organizations should prioritize the security of systems running this software. While awaiting a vendor-supplied patch, ensure that endpoint detection and response tools are configured to alert on suspicious behavior involving the SAS Core Service, and limit user access to the affected hosts to mitigate the risk of initial exploitation.

More RealDefense CVEs

Sources