CVE-2025-14497

7.8

RealDefense · SUPERAntiSpyware

RealDefense SUPERAntiSpyware contains an exposed dangerous function in the SAS Core Service, allowing local attackers to escalate privileges to SYSTEM.

Executive summary

A local privilege escalation vulnerability in RealDefense SUPERAntiSpyware allows low-privileged attackers to gain full SYSTEM control over the affected host.

Vulnerability

The vulnerability resides in the SAS Core Service, where an exposed dangerous function can be exploited by an authenticated local user. By interacting with this function, a low-privileged attacker can execute arbitrary code with SYSTEM-level permissions.

Business impact

The ability for a local user to escalate to SYSTEM privileges poses a severe risk to organizational security, as it facilitates full system compromise, data exfiltration, and the potential for persistent malware installation. With a CVSS score of 7.8, this flaw is categorized as High severity: it represents a significant threat to the confidentiality, integrity, and availability of the host machine.

Remediation

Immediate Action: Contact the vendor or monitor official security bulletins for the release of a patched version of the SAS Core Service.

Proactive Monitoring: Audit local system logs for unauthorized processes attempting to interact with the SAS Core Service or unusual escalations in user privilege levels.

Compensating Controls: Restrict local user access on critical systems to the principle of least privilege, and ensure that only authorized users can execute code on systems where SUPERAntiSpyware is installed.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for complete system takeover, administrators should treat this vulnerability with high priority. While an official patch is pending, organizations must implement strict access controls to limit the number of users capable of executing code on systems running the affected software. Monitor vendor communication channels closely for the release of the remediation update.

More RealDefense CVEs

Sources