CVE-2025-14495
Unknown Unknown - Not Provided
Local Privilege Escalation via Exposed Function in SUPERAntiSpyware

Publication date: 2025-12-23

Last updated on: 2025-12-23

Assigner: Zero Day Initiative

Description
RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of RealDefense SUPERAntiSpyware. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the SAS Core Service. The issue results from an exposed dangerous function. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-27677.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-12-23
Last Modified
2025-12-23
Generated
2026-05-07
AI Q&A
2025-12-24
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
realdefense superantispyware 3.0
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-749 The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in the SAS Core Service of RealDefense SUPERAntiSpyware and involves an exposed dangerous function. It allows a local attacker, who already has the ability to run low-privileged code on the system, to escalate their privileges to SYSTEM level and execute arbitrary code with high privileges.


How can this vulnerability impact me? :

If exploited, this vulnerability can allow an attacker to gain SYSTEM-level privileges on the affected system. This means the attacker can execute arbitrary code with the highest level of access, potentially leading to full control over the system, compromising confidentiality, integrity, and availability of data and system resources.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart