PT-2025-52478 · Realdefense · Superantispyware

Gongjae

·

Published

2025-12-19

·

Updated

2025-12-24

·

CVE-2025-14494

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RealDefense SUPERAntiSpyware (affected versions not specified)
Description A local attacker can escalate privileges on installations of RealDefense SUPERAntiSpyware by exploiting an exposed dangerous function within the SAS Core Service. Successful exploitation allows an attacker to execute arbitrary code with SYSTEM-level privileges, but requires initial low-privileged code execution on the target system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Weakness Enumeration

Related Identifiers

CVE-2025-14494
ZDI-25-1163

Affected Products

Superantispyware