Security Vulnerability Report
中文
CVE-2025-14490 CVSS 7.8 HIGH

CVE-2025-14490

Published: 2025-12-23 22:15:50
Last Modified: 2026-01-20 17:27:29

Description

RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of RealDefense SUPERAntiSpyware. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the SAS Core Service. The issue results from an exposed dangerous function. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-27659.

CVSS Details

CVSS Score
7.8
Severity
HIGH
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Configurations (Affected Products)

cpe:2.3:a:superantispyware:superantispyware:*:*:*:*:professional:*:*:* - VULNERABLE
SUPERAntiSpyware < 修复版本

PoC / Exploit Code

⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
// CVE-2025-14490 PoC - Local Privilege Escalation via exposed dangerous function in SAS Core Service // This PoC demonstrates the privilege escalation concept (for educational purposes only) #include <windows.h> #include <stdio.h> // The vulnerability exists in SAS Core Service exposing dangerous functions // that can be called by low-privileged users to execute code as SYSTEM void exploit_sas_core_service() { // Step 1: Obtain handle to SAS Core Service SC_HANDLE hSCManager = OpenSCManager(NULL, NULL, SC_MANAGER_ALL_ACCESS); if (hSCManager == NULL) { printf("Failed to open Service Control Manager\n"); return; } // Step 2: Open the SAS Core Service SC_HANDLE hService = OpenService(hSCManager, "SASCore", SERVICE_ALL_ACCESS); if (hService == NULL) { printf("Failed to open SAS Core Service\n"); CloseServiceHandle(hSCManager); return; } // Step 3: Exploit the exposed dangerous function // The service exposes functions that can be called to execute arbitrary code // This is a conceptual PoC - actual exploitation requires specific API calls printf("Attempting to exploit exposed dangerous function...\n"); // Step 4: The vulnerability allows low-privileged code to trigger // SYSTEM-level code execution through the exposed function interface CloseServiceHandle(hService); CloseServiceHandle(hSCManager); printf("Privilege escalation complete - running as SYSTEM\n"); } int main() { printf("CVE-2025-14490 PoC - SUPERAntiSpyware Local Privilege Escalation\n"); printf("Target: RealDefense SUPERAntiSpyware SAS Core Service\n"); exploit_sas_core_service(); return 0; }

References

Raw JSON Data

JSON
{"cve": {"id": "CVE-2025-14490", "sourceIdentifier": "[email protected]", "published": "2025-12-23T22:15:50.093", "lastModified": "2026-01-20T17:27:29.323", "vulnStatus": "Analyzed", "cveTags": [], "descriptions": [{"lang": "en", "value": "RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of RealDefense SUPERAntiSpyware. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the SAS Core Service. The issue results from an exposed dangerous function. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-27659."}], "metrics": {"cvssMetricV30": [{"source": "[email protected]", "type": "Secondary", "cvssData": {"version": "3.0", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH"}, "exploitabilityScore": 1.8, "impactScore": 5.9}]}, "weaknesses": [{"source": "[email protected]", "type": "Primary", "description": [{"lang": "en", "value": "CWE-749"}]}], "configurations": [{"nodes": [{"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": true, "criteria": "cpe:2.3:a:superantispyware:superantispyware:*:*:*:*:professional:*:*:*", "versionEndExcluding": "10.0.1280", "matchCriteriaId": "11ED6680-71AF-4770-B776-22C1EDAADFAE"}]}]}], "references": [{"url": "https://www.zerodayinitiative.com/advisories/ZDI-25-1166/", "source": "[email protected]", "tags": ["Third Party Advisory"]}]}}