Impact
The vulnerability resides in the kernel driver pgsecdl.sys that ships with Unistal Systems Pvt. Ltd. Protegent 360 v2.0.0.4. Because the driver does not enforce proper authorization checks, a local attacker can execute code in kernel mode and elevate their privileges to that of SYSTEM. An attacker who already has local access could therefore compromise the entire machine with administrator rights. This reflects a classic privilege-escalation flaw that bypasses the operating-system security model.
Affected Systems
This issue affects Unistal Systems Pvt. Ltd. Protegent 360 version 2.0.0.4. No other versions or vendors are listed as affected in the current data.
Risk and Exploitability
The attack vector is local, requiring the attacker to have physical or software access to the operated machine. The CVSS score of 7.8 indicates a high severity, while the EPSS score of less than 1 % shows that the probability of exploitation is currently very low but not zero. The vulnerability is not listed in the CISA KEV catalog, indicating no publicly known active exploits yet. Nevertheless, because the flaw enables full-privilege code execution at kernel level, it represents a significant threat that could allow an attacker to control, modify, or disrupt the system.
OpenCVE Enrichment