CVE-2026-38764
Deferred Deferred - Pending Action

Privilege Escalation in Protegent 360 via pgsecdl.sys

Vulnerability report for CVE-2026-38764, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-23

Last updated on: 2026-07-30

Assigner: MITRE

Description

An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-23
Last Modified
2026-07-30
Generated
2026-08-13
AI Q&A
2026-07-24
EPSS Evaluated
2026-08-11
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
unistal_systems_pvt_ltd protegent_360 2.0.0.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-782 The product implements an IOCTL with functionality that should be restricted, but it does not properly enforce access control for the IOCTL.
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a local privilege escalation issue in Unistal Systems Pvt. Ltd. Protegent 360 v2.0.0.4. It is caused by a flaw in the kernel driver pgsecdl.sys, which allows a local attacker to gain elevated privileges on the system.

Impact Analysis

If exploited, this vulnerability could allow an attacker with local access to your system to escalate their privileges. This could lead to unauthorized control over your system, potential data theft, installation of malicious software, or other harmful actions.

Compliance Impact

This vulnerability involves a local privilege escalation in Unistal Systems Pvt. Ltd. Protegent 360 v2.0.0.4 via a kernel driver. Such vulnerabilities can potentially allow unauthorized access or control, which may impact compliance with standards like GDPR or HIPAA by compromising data integrity, confidentiality, or availability.

Mitigation Strategies

Immediately uninstall or disable Protegent 360 v2.0.0.4 and its kernel driver pgsecdl.sys to prevent privilege escalation. Update to the latest patched version if available. Monitor system logs for suspicious activity related to the driver.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-38764. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart