CVE-2026-38764

7.8

Unistal Systems Pvt. Ltd. · Protegent 360

A local privilege escalation vulnerability exists in the Unistal Systems Protegent 360 kernel driver pgsecdl.sys, which could allow a local attacker to gain elevated system privileges.

Executive summary

A vulnerability in the Unistal Systems Protegent 360 kernel driver allows a local attacker to achieve full privilege escalation, posing a significant risk to host integrity.

Vulnerability

The flaw resides within the pgsecdl.sys kernel driver, which fails to properly sanitize or control access, allowing an authenticated local user with low privileges to execute code with kernel-level permissions.

Business impact

Successful exploitation grants an attacker full control over the affected workstation or server, leading to potential data theft, malware persistence, or complete system compromise. Given the CVSS score of 7.8, this high-severity vulnerability represents a significant risk to organizational security, as it bypasses standard user-level access controls to manipulate the underlying operating system.

Remediation

Immediate Action: Contact Unistal Systems support to inquire about a patched version of the Protegent 360 software or a hotfix for the pgsecdl.sys driver.

Proactive Monitoring: Monitor system logs for unauthorized attempts to load or interact with kernel-mode drivers and alert on suspicious process execution originating from low-privileged user accounts.

Compensating Controls: Restrict local user access to the system, implement application control policies to prevent unauthorized binaries from running, and utilize Endpoint Detection and Response (EDR) tools to detect kernel-level anomalies.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept repository exists on GitHub.

Analyst recommendation

Organizations utilizing Protegent 360 version 2.0.0.4 should treat this vulnerability with high priority due to the availability of proof-of-concept code. Administrators must restrict local user permissions to the absolute minimum required for operations and verify the status of the driver with the vendor to ensure that remediation is applied as soon as a patch becomes available.

More Unistal Systems Pvt. Ltd. CVEs

Sources