[CVE-2026-55978] Improper Access Control in IOCTL Handler Leading to Security Policy Bypass

CVE ID

CVE-2026-55978 | 8.4 (High)

An improper access control vulnerability in CatchPulse could allow a non-administrative local attack to connect to an unrestricted kernel filter communication port and bypass CatchPulse’s security policy Enforcement.

Affected & Fixed Versions
Product Vulnerable Version Fixed Version Status

CatchPulse 

v10.10.0 and earlier
10.10.1

✓Resolved

Recommended Action

Users and administrators of affected products are advised to update to the latest versions.

Acknowledgement

SecureAge thanks Ms Ang Kar Min for responsibly disclosing this issue through coordinated vulnerability disclosure.

Advisory Details
Status

✓ Resolved

Severity

High

Product

CatchPulse

Platform

Windows

Attack Type

Local