Tag

#Local Privilege Escalation

newsHIGH 7.8

Integer Overflow Vulnerability in WinFsp (CVE-2026-7162)

A high-severity integer overflow vulnerability (CVE-2026-7162) has been discovered in WinFsp, a software package. Successful exploitation could allow an attacker to achieve system-level access. Affected versions include WinFsp 2.2.26112 and lower.

1 source
newsHIGH 7.8

CVE-2026-15506: SecureAge CatchPulse Heap-Based Buffer Overflow Vulnerability

A heap-based buffer overflow vulnerability has been detected in SecureAge CatchPulse up to version 10.9.3. The vulnerability is located in the library saappctl.sys of the Driver component and requires local access to be exploited. A CVSS score of 7.8 indicates a high severity level.

1 source
blogMEDIUM 5.3

Understanding and Defending Against Command Injection in ANTLR4

This educational analysis focuses on CVE-2026-13501, a command injection vulnerability in ANTLR4 up to version 4.13.2. The vulnerability allows for local command injection through the manipulation of the GoTarget function in the GoTarget.java file. Understanding the root cause, attack surface, and exploitation mechanics is crucial for security practitioners to defend against such threats.

1 source
articleHIGH 8.5

Local Privilege Escalation Vulnerability in Acer NitroSense Software

A Local Privilege Escalation (LPE) vulnerability affects Acer NitroSense software versions prior to 3.01.3052. The vulnerability is caused by the PSAdminAgent service creating a Named Pipe with a weak Access Control List (ACL), allowing any authenticated local user to connect and send commands, and delete arbitrary files with system authority.

1 source