CVE-2025-14496

7.8

RealDefense · SUPERAntiSpyware

A local privilege escalation vulnerability in the RealDefense SUPERAntiSpyware SAS Core Service allows low-privileged attackers to execute arbitrary code with SYSTEM-level permissions.

Executive summary

A critical local privilege escalation vulnerability in RealDefense SUPERAntiSpyware allows low-privileged users to achieve full system compromise.

Vulnerability

The flaw resides within the SAS Core Service, where an exposed dangerous function permits an attacker to perform unauthorized operations. An attacker must already possess the ability to execute low-privileged code on the local system to trigger this escalation.

Business impact

The ability for a low-privileged user to escalate to SYSTEM-level access represents a complete compromise of host integrity. Given the CVSS score of 7.8, this vulnerability poses a high risk to business operations as it allows an attacker to bypass security controls, install persistent malware, or exfiltrate sensitive data, leading to significant reputational and operational damage.

Remediation

Immediate Action: Monitor the vendor for the release of a security update and apply the patch as soon as it becomes available.

Proactive Monitoring: Review system logs for unusual process execution patterns originating from the SAS Core Service or unexpected privilege changes on local user accounts.

Compensating Controls: Restrict local user access and ensure that only authorized users can execute code on systems where this software is installed to prevent the prerequisite condition for exploitation.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This vulnerability presents a high risk due to the potential for full system compromise from a low-privileged state. IT administrators should prioritize monitoring the vendor advisory for a patch release and prepare to deploy the update across all affected endpoints immediately upon availability to mitigate the risk of local privilege escalation.

More RealDefense CVEs

Sources