CVE-2026-38763
Deferred Deferred - Pending Action

Denial of Service in Protegent 360

Vulnerability report for CVE-2026-38763, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-22

Last updated on: 2026-07-24

Assigner: MITRE

Description

An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to cause a denial of service via the function sub_13828

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-22
Last Modified
2026-07-24
Generated
2026-08-12
AI Q&A
2026-07-23
EPSS Evaluated
2026-08-10
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
unistal_systems_pvt_ltd protegent_360 2.0.0.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-703 The product does not properly anticipate or handle exceptional conditions that rarely occur during normal operation of the product.
CWE-404 The product does not release or incorrectly releases a resource before it is made available for re-use.
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a denial of service issue in Unistal Systems Pvt. Ltd. Protegent 360 v2.0.0.4 caused by a local attacker exploiting the function sub_13828.

Detection Guidance

Detecting this vulnerability requires checking for the presence of vulnerable drivers and their exposed IOCTLs. Inspect system drivers for wscsrv.sys and pgsecdl.sys in C:\Windows\system32\drivers. Use tools like Process Explorer or driverquery.exe to list loaded drivers. Check for IOCTL exposure with commands like fltmc or WinObj to inspect device objects.

Impact Analysis

A local attacker could exploit this to cause the system to crash or become unavailable, disrupting normal operations.

Compliance Impact

This vulnerability allows local attackers to bypass security controls, overwrite system files, and crash the kernel, which could lead to unauthorized access or data breaches. Such failures in security software may violate compliance requirements under GDPR (data protection) and HIPAA (health data security) by failing to ensure integrity and confidentiality of systems handling sensitive data.

Mitigation Strategies

Update Protegent 360 to the latest version if a patch is available. Disable the vulnerable function if possible. Restrict local access to the system to trusted users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-38763. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart