Impact
An issue exists in the kernel driver pgsecdl.sys used by Unistal Systems Pvt. Ltd. Protegent 360 and allows a local attacker to gain higher privileges on the affected system. The vulnerability stems from incorrect privilege assignments within the driver, enabling an attacker with local access to elevate privileges to system level. The weakness is classified under CWE-269 and CWE-782, indicating a flaw in privilege management and unauthorized access to a critical system component.
Affected Systems
The affected system is Protogent 360 version 2.0.0.4, a kernel‑level antivirus solution distributed by Unistal Systems Pvt. Ltd. No other version or product information is provided in the CVE data.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability, but the EPSS score of less than 1% suggests that, as of the assessment, exploitation is considered unlikely or not widely observed. The vulnerability is not listed in CISA’s KEV catalog, meaning it may not be publicly exploited yet. The attack vector is inferred to require local access to the system, as the driver operates in kernel mode and the description states that a local attacker can exploit it. The defender should assume a local privileged user or a malicious local process could trigger the elevation, so the risk is high for environments where untrusted code could run locally.
OpenCVE Enrichment