Description
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys
Published: 2026-07-22
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the kernel driver pgsecdl.sys that ships with Unistal Systems Pvt. Ltd. Protegent 360 v2.0.0.4. Because the driver does not enforce proper authorization checks, a local attacker can execute code in kernel mode and elevate their privileges to that of SYSTEM. An attacker who already has local access could therefore compromise the entire machine with administrator rights. This reflects a classic privilege-escalation flaw that bypasses the operating-system security model.

Affected Systems

This issue affects Unistal Systems Pvt. Ltd. Protegent 360 version 2.0.0.4. No other versions or vendors are listed as affected in the current data.

Risk and Exploitability

The attack vector is local, requiring the attacker to have physical or software access to the operated machine. The CVSS score of 7.8 indicates a high severity, while the EPSS score of less than 1 % shows that the probability of exploitation is currently very low but not zero. The vulnerability is not listed in the CISA KEV catalog, indicating no publicly known active exploits yet. Nevertheless, because the flaw enables full-privilege code execution at kernel level, it represents a significant threat that could allow an attacker to control, modify, or disrupt the system.

Generated by OpenCVE AI on August 4, 2026 at 00:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied update that patches the pgsecdl.sys driver or upgrade to a newer version of Protegent 360 that contains the fix.
  • If no patch is available, uninstall or disable the pgsecdl.sys kernel driver to eliminate the attack surface.
  • Restrict local console or remote desktop access to authorized users, enforce strong authentication, and limit local user privileges to reduce the chance that a local attacker can load the vulnerable driver.
  • Monitor security logs for abnormal driver‑loading events and audit user sign‑in records to detect potential abuse.
  • Maintain an inventory of installed kernel drivers and apply timely updates for all proprietary drivers.

Generated by OpenCVE AI on August 4, 2026 at 00:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Protegent 360 Kernel Driver

Thu, 30 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Protegent 360 Kernel Driver

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Unistal Systems
Unistal Systems protegent 360
Vendors & Products Unistal Systems
Unistal Systems protegent 360

Sun, 26 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Protegent Kernel Driver
Weaknesses CWE-264

Fri, 24 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-782
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Protegent Kernel Driver
Weaknesses CWE-264

Wed, 22 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys
References

Subscriptions

Unistal Systems Protegent 360
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-24T19:47:24.642Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-38765

cve-icon Vulnrichment

Updated: 2026-07-24T19:47:00.636Z

cve-icon NVD

Status : Deferred

Published: 2026-07-22T23:16:35.390

Modified: 2026-07-24T20:17:04.950

Link: CVE-2026-38765

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:30:18Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-782

    Exposed IOCTL with Insufficient Access Control