Description
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_186f4 function
Published: 2026-07-22
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An issue in Protegent 360 v2.0.0.4 allows a local attacker to gain higher privileges by exploiting the sub_186f4 function. The vulnerability enables elevation of user rights and access to protected resources, potentially allowing the attacker to take full control of the affected system.

Affected Systems

The affected product is Protegent 360 v2.0.0.4 from Unistal Systems Pvt. Ltd.

Risk and Exploitability

The vulnerability has a CVSS score of 7.8 and an EPSS score of less than 1%, and it is not listed in the CISA KEV catalog. The attack requires local access to the target machine, making the risk contingent on the presence of vulnerable users with sufficient authority. If a privileged user can execute the vulnerable component, the attacker can compromise the system’s integrity and confidentiality.

Generated by OpenCVE AI on August 4, 2026 at 00:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check with Unistal Systems for a patch or newer release of Protegent 360 that resolves the sub_186f4 issue and install it immediately.
  • If a patch is unavailable, restrict local user accounts from running Protegent 360 or the sub_186f4 function to eliminate the privilege escalation path.
  • If the software is not essential, uninstall or disable Protegent 360 to remove the vulnerability from the attack surface.

Generated by OpenCVE AI on August 4, 2026 at 00:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title Protegent 360 v2.0.0.4 Local Privilege Escalation via sub_186f4

Thu, 30 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Protegent 360 v2.0.0.4 Local Privilege Escalation via sub_186f4

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Unistal Systems
Unistal Systems protegent 360
Vendors & Products Unistal Systems
Unistal Systems protegent 360

Mon, 27 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Local Credential Escalation via sub_186f4 in Protegent 360
Weaknesses CWE-284
CWE-755

Fri, 24 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-782
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Local Credential Escalation via sub_186f4 in Protegent 360
Weaknesses CWE-284
CWE-755

Wed, 22 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_186f4 function
References

Subscriptions

Unistal Systems Protegent 360
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-24T19:51:55.060Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-38766

cve-icon Vulnrichment

Updated: 2026-07-24T19:51:16.605Z

cve-icon NVD

Status : Deferred

Published: 2026-07-22T23:16:35.537

Modified: 2026-07-24T20:17:05.120

Link: CVE-2026-38766

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:30:18Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-782

    Exposed IOCTL with Insufficient Access Control