Vulnerability Details
| Attribute | Value |
|---|---|
| CWE | CWE-732 — Incorrect Permission Assignment for Critical Resource |
| Affected component | saappsvc.exe (SecureAge Application Whitelisting Service) |
| Primary pipes | \\.\pipe\SAAppWhitelistingService; \\.\pipe\SecureAgeUniversalAV |
| Total NULL DACL pipes | 10 (all CatchPulse named pipes; confirmed with Sysinternals accesschk64) |
| CVSS 3.1 vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:L |
| CVSS 3.1 score | 5.2 Medium |
| Affected versions | v10.9.3, v10.10.0 |
SAAppWhitelistingService Handler
Handler function: 0x14006CF60. Wire format: [int32 size=8][int32 cmd] (8 bytes).
All dispatched commands execute as SYSTEM with no privilege verification.
| cmd | Action | Impact |
|---|---|---|
1 | Initialises the application whitelisting subsystem | Any standard user can reset / reinitialise the whitelist subsystem |
2 | Starts or aborts a quick rewhitelist scan | Disrupts active whitelist scan operations |
3 | Aborts or resets an ongoing scan | Aborts or resets an ongoing scan |
4 | Writes system information to HKLM as SYSTEM | SYSTEM-context HKLM write triggered by standard user; no privilege check |
5+ | — | Returns 0x32 (NOT_SUPPORTED) |
Security Impact
SecureAgeUniversalAV pipe also carries a NULL DACL.
Through cmd=2, a standard local user can retrieve approximately 200 bytes of UTF-16LE
product-status text, including whether a full system scan is in progress or whether the computer is at risk.
This does not expose user files, credentials, tokens, keys, PII, or protected content, but it reveals live
security-product state with limited tactical value. This supports the accepted C:L rating.
SAAppWhitelistingService without caller verification. Confirmed operations include
reinitialising the application-whitelisting subsystem, controlling scan operations, and triggering
the affected service's machine-level registry operation.
SAAppWhitelistingService), or start/abort a full system scan via
\\.\pipe\SAFullSystemScan (cmd=1, cmd=2) — both pipes carry a NULL DACL.
Proof of Concept
The finding was validated from a standard user account without administrator rights or custom executables. Proof-of-concept code was provided privately during coordinated disclosure and is intentionally not being released publicly.
Confirmed output:
[*] Running as: TESTING\test
[*] cmd=1 -> 08 00 00 00 08 00 00 00 00 00 00 00 (response received - executed as SYSTEM)
[*] cmd=4 -> 08 00 00 00 08 00 00 00 00 00 00 00 (response received - executed as SYSTEM)
Remediation
- Apply a restrictive DACL (administrator-only or service-account-only) at pipe creation time for all pipes that execute privileged operations.
- Add handler-level privilege verification to
SAAppWhitelistingServicecmd=1–4 as defence-in-depth.