CVE-2026-55980 — SecureAge CatchPulse Security Advisory

CVE-2026-55980

Stack Buffer Overrun / saappsvc.exe service denial of service

CVSS 3.1 Score

5.5 Medium

Versions confirmed

v10.10.0 and earlier

Access required

Standard local user

Vendor: SecureAge Technology  |  Product: CatchPulse

Reporter: Ang Kar Min  |  Report date: 2026-07-04  |  Public disclosure: 2026-08-06

Core finding

A standard local user can connect to \\.\pipe\SecureAgeApplicationWhitelisting (NULL DACL), spoof a SYSTEM process identity using a PID supplied in the message body, and send a cmd=4 payload that triggers a stack buffer overrun in saappsvc.exe. The service crashes (STATUS_STACK_BUFFER_OVERRUN) and cannot be restarted by the standard user — administrator intervention or system reboot is required. The kernel driver (saappctl.sys) retains its in-memory enforcement state after the crash; application whitelisting continues to block previously blocked binaries. The confirmed impact is denial-of-service of the security service.

Vulnerability Details

AttributeValue
CWECWE-121 (Stack-based Buffer Overflow); CWE-290 (Authentication Bypass by Spoofing)
Affected componentsaappsvc.exe (SecureAge Application Whitelisting Service)
Affected pipe\\.\pipe\SecureAgeApplicationWhitelisting (NULL DACL)
Exception code0xC0000409 (STATUS_STACK_BUFFER_OVERRUN)
Fault offset0x87f6b in saappsvc.exe (within __report_gsfailure)
CVSS 3.1 vectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 3.1 score5.5 Medium
Versions confirmedv10.9.3, v10.10.0
Code execution / LPENot demonstrated; current confirmed impact is service denial of service.

Root Cause

1. Identity Check Uses Attacker-Controlled PID

The cmd=4 handler at 0x14006C671 reads a process ID from the message body at offset 0x02 and calls OpenProcess on that PID to retrieve a token, which is then compared against the TrustedAccount registry key. It does not call GetNamedPipeClientToken to verify the actual pipe client. Any standard user can supply the PID of a SYSTEM process (e.g., lsass.exe, which is queryable via PROCESS_QUERY_LIMITED_INFORMATION) to pass this check, since SYSTEM is listed in TrustedAccount.

2. Stack Buffer Overrun in sub_6A120

After identity verification, the handler passes attacker-controlled payload fields to sub_6A120 (RVA 0x6A120), which writes processed payload data into a stack buffer without sufficient bounds checking. The write corrupts the MSVC /GS stack cookie. __security_check_cookie detects the corruption and __report_gsfailure raises STATUS_STACK_BUFFER_OVERRUN, terminating the service process.

Call Chain

FunctionRVARole
cmd=4 handler0x6C671PID identity check; dispatches to processing function; frame 0xA70 bytes
sub_6A1200x6A120Overflowing function; unbounded write corrupts the /GS cookie
sub_8AEF00x8AEF0Processing stub called by sub_6A120; writes into the overflowing buffer; no bounds check
sub_806400x80640__security_check_cookie; CMP RAX vs global cookie; BND JNE to __report_gsfailure on mismatch
__report_gsfailure~0x87E99Raises STATUS_STACK_BUFFER_OVERRUN (0xC0000409); terminates the process

Proof-of-concept code was provided privately during coordinated disclosure and is intentionally not being released publicly.

Security Impact

Denial of Service (confirmed): saappsvc.exe terminates. Standard users cannot restart the service (sc start SAAppSvc returns Access Denied, error 5). Administrator intervention or system reboot is required.
Enforcement bypass: NOT confirmed. Post-crash dynamic testing (canary binaries previously blocked by policy) confirmed that saappctl.sys retains its in-memory enforcement state after saappsvc.exe crashes. The kernel driver does not re-read AppWhitelistingMode from the registry on service failure; previously-blocked binaries remain blocked. The AppWhitelistingMode = 0 registry value reflects the crash state but does not alter live kernel enforcement. CVSS I:N reflects this finding.
Code execution / local privilege escalation: not demonstrated. The crash is caught by the compiler stack-cookie protection path and terminates the process through STATUS_STACK_BUFFER_OVERRUN. No code execution path was confirmed during testing. CVSS C:N and I:N reflect this finding.

Proof of Concept

The finding was validated from a standard user account without administrator rights or custom executables. Proof-of-concept code was provided privately during coordinated disclosure and is intentionally not being released publicly.

Confirmed output (running as TESTING\test, standard user):

[+] Connected as: TESTING\test  (standard user, no admin rights)
[*] Sending cmd=4 with lsass PID=1032 at offset 0x02 (0x300 bytes)...

Service status: Stopped
[+] CONFIRMED: saappsvc.exe is no longer running
[*] AppWhitelistingMode=0 in registry (reflects crash state; kernel enforcement unaffected)
[!] sc start SAAppSvc -> [SC] OpenService FAILED 5: Access is denied.

Remediation

  • Pipe DACL: Apply an administrator-only or service-account-only DACL to \\.\pipe\SecureAgeApplicationWhitelisting at pipe creation time. Standard users should not be able to connect.
  • Identity check: Replace the PID-from-message-body identity verification with GetNamedPipeClientToken to obtain the actual pipe client's token. Attacker-supplied PID values in the message body must never be used for privilege or identity decisions.
  • Bounds checking: Add explicit length bounds to the payload processing function called by cmd=4 to prevent the stack overrun irrespective of any access control fix.