Impact
This vulnerability is a heap overflow in the certificate parsing function of Absolute Security Secure Access clients prior to version 14.55. It allows a local attacker with administrator permissions to manipulate the parsing process, triggering an out-of-bounds write that leads to a denial of service of the client application. The weakness is a classic out-of-bounds write (CWE‑787), causing loss of availability for users relying on the client.
Affected Systems
Affected products are Absolute Security Secure Access clients with versions earlier than 14.55. Administrators with local system access to these clients are required to exploit the flaw.
Risk and Exploitability
The CVSS base score of 6.7 indicates moderate severity, while the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, and exploitation requires local administrative access, which limits its attack surface. Nonetheless, once an authorized local user activates the payload, the client will crash and become unavailable until the process is restarted or the software is upgraded.
OpenCVE Enrichment