CVE-2026-55979 — SecureAge CatchPulse Security Advisory

CVE-2026-55979

Named Pipe NULL DACL / unprivileged SYSTEM-level operations

CVSS 3.1 Score

5.2 Medium

Affected versions

v10.10.0 and earlier

Access required

Standard local user

Vendor: SecureAge Technology  |  Product: CatchPulse

Reporter: Ang Kar Min  |  Report date: 2026-07-04  |  Public disclosure: 2026-08-06

Core finding

All CatchPulse named pipes carry a NULL DACL. The \\.\pipe\SAAppWhitelistingService pipe dispatches privileged commands in the SYSTEM context with no caller verification, allowing any standard user to manipulate the application whitelisting subsystem.

Vulnerability Details

AttributeValue
CWECWE-732 — Incorrect Permission Assignment for Critical Resource
Affected componentsaappsvc.exe (SecureAge Application Whitelisting Service)
Primary pipes\\.\pipe\SAAppWhitelistingService; \\.\pipe\SecureAgeUniversalAV
Total NULL DACL pipes10 (all CatchPulse named pipes; confirmed with Sysinternals accesschk64)
CVSS 3.1 vectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:L
CVSS 3.1 score5.2 Medium
Affected versionsv10.9.3, v10.10.0

SAAppWhitelistingService Handler

Handler function: 0x14006CF60. Wire format: [int32 size=8][int32 cmd] (8 bytes). All dispatched commands execute as SYSTEM with no privilege verification.

cmdActionImpact
1Initialises the application whitelisting subsystemAny standard user can reset / reinitialise the whitelist subsystem
2Starts or aborts a quick rewhitelist scanDisrupts active whitelist scan operations
3Aborts or resets an ongoing scanAborts or resets an ongoing scan
4Writes system information to HKLM as SYSTEMSYSTEM-context HKLM write triggered by standard user; no privilege check
5+—Returns 0x32 (NOT_SUPPORTED)

Security Impact

Information disclosure (Low): The SecureAgeUniversalAV pipe also carries a NULL DACL. Through cmd=2, a standard local user can retrieve approximately 200 bytes of UTF-16LE product-status text, including whether a full system scan is in progress or whether the computer is at risk. This does not expose user files, credentials, tokens, keys, PII, or protected content, but it reveals live security-product state with limited tactical value. This supports the accepted C:L rating.
Privileged operations: Any standard local user can invoke commands handled by SAAppWhitelistingService without caller verification. Confirmed operations include reinitialising the application-whitelisting subsystem, controlling scan operations, and triggering the affected service's machine-level registry operation.
Availability (Low): Any standard user can abort or reset an active whitelist scan (cmd=2, cmd=3 on SAAppWhitelistingService), or start/abort a full system scan via \\.\pipe\SAFullSystemScan (cmd=1, cmd=2) — both pipes carry a NULL DACL.

Proof of Concept

The finding was validated from a standard user account without administrator rights or custom executables. Proof-of-concept code was provided privately during coordinated disclosure and is intentionally not being released publicly.

Confirmed output:

[*] Running as: TESTING\test
[*] cmd=1 -> 08 00 00 00 08 00 00 00 00 00 00 00  (response received - executed as SYSTEM)
[*] cmd=4 -> 08 00 00 00 08 00 00 00 00 00 00 00  (response received - executed as SYSTEM)

Remediation

  • Apply a restrictive DACL (administrator-only or service-account-only) at pipe creation time for all pipes that execute privileged operations.
  • Add handler-level privilege verification to SAAppWhitelistingService cmd=1–4 as defence-in-depth.