Impact
The vulnerability is an improper access control flaw that allows a non‑administrative local user to connect to an unrestricted kernel filter communication port in CatchPulse. By doing so the attacker can bypass the software’s security policy enforcement, effectively elevating privileges and accessing protected resources. This flaw directly exposes system integrity and availability to unauthorized manipulation.
Affected Systems
SecureAge’s CatchPulse application is affected. No specific product versions were listed in the advisory, so all deployed versions prior to the patch are potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.4 indicates a high‑severity risk and the omission of an EPSS score means we cannot quantify current exploitation probability. The vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits yet. The attack vector is inferred to be local, requiring a non‑administrative user with access to the host, or an attacker who can execute code locally. Given the direct connection to a kernel‑level communication channel, a successful exploitation would allow the attacker to bypass high‑level security controls and potentially modify system behavior.
OpenCVE Enrichment