Description
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to cause a denial of service via the function sub_13828
Published: 2026-07-22
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An issue in Unistal Systems Pvt. Ltd.’s Protogent 360 v2.0.0.4 permits a local user to invoke the internal function sub_13828, causing the antivirus service to become unresponsive or terminate unexpectedly. The resulting denial of service disables real‑time protection, allowing malware to run unchecked while the service is in a failed state. The flaw does not grant code execution or privilege escalation, but it disrupts the availability of the security product.

Affected Systems

The product affected is Protogent 360 v2.0.0.4 from Unistal Systems Pvt. Ltd. No other vendors or versions are listed as impacted.

Risk and Exploitability

The CVSS score of 5.5 indicates a medium severity, and the EPSS score of less than 1% indicates low probability of public exploitation. Because the flaw requires local access, an attacker must already have physical or console access to the target machine. The vulnerability is not listed in CISA KEV, implying no known active exploitation. When triggered, the denial of service could allow other malicious processes to run unchecked while the antivirus is unavailable, but it does not grant further privileges or remote attack capabilities.

Generated by OpenCVE AI on August 4, 2026 at 00:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Protogent 360 to the latest available release that contains the repair; if none exist, contact Unistal Systems for an advisory or temporary fix.
  • Run the antivirus operation under a dedicated service account with the minimum privileges required; this limits the impact of a crash on the broader system.
  • Configure automated service monitoring and recovery so that the antivirus restarts promptly after a failure and administrators receive alerts of repeated crashes.
  • Enforce strict local access controls—restrict console login to trusted administrators—to reduce the risk of a local attacker triggering the flaw.

Generated by OpenCVE AI on August 4, 2026 at 00:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Title Local Denial of Service in Protogent 360 Antivirus via sub_13828

Thu, 30 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Local Denial of Service via sub_13828 in Protogent 360 v2.0.0.4

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Unistal Systems
Unistal Systems protegent 360
Vendors & Products Unistal Systems
Unistal Systems protegent 360

Fri, 24 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-404
CWE-703
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Local Denial of Service via sub_13828 in Protogent 360 v2.0.0.4
Weaknesses CWE-400

Wed, 22 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to cause a denial of service via the function sub_13828
References

Subscriptions

Unistal Systems Protegent 360
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-24T19:54:02.771Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-38763

cve-icon Vulnrichment

Updated: 2026-07-24T19:44:20.512Z

cve-icon NVD

Status : Deferred

Published: 2026-07-22T23:16:35.143

Modified: 2026-07-24T20:17:04.600

Link: CVE-2026-38763

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:30:18Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-404

    Improper Resource Shutdown or Release

  • CWE-703

    Improper Check or Handling of Exceptional Conditions