CVE-2024-27518

HIGH

SUPERAntiSpyware Professional X 10.0.1262-10.0.1264 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-27518. PoCs published by secunnix.

AI-analyzed exploit summary This repository contains a working PoC for CVE-2024-27518, a local privilege escalation vulnerability in SUPERAntiSpyware Professional X. The exploit leverages DLL hijacking via a malicious 'version.dll' file restored from quarantine to achieve SYSTEM privileges.

Description

An issue in SUPERAntiSyware Professional X 10.0.1262 and 10.0.1264 allows unprivileged attackers to escalate privileges via a restore of a crafted DLL file into the C:\Program Files\SUPERAntiSpyware folder.

Exploits (1)

nomisec WORKING POC
by secunnix · poc
https://github.com/secunnix/CVE-2024-27518

This repository contains a working PoC for CVE-2024-27518, a local privilege escalation vulnerability in SUPERAntiSpyware Professional X. The exploit leverages DLL hijacking via a malicious 'version.dll' file restored from quarantine to achieve SYSTEM privileges.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: SUPERAntiSpyware Professional X <=10.0.1262
No auth needed
Prerequisites: Local access to the target system · SUPERAntiSpyware installed · Ability to create and quarantine a malicious DLL
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3

Scores

CVSS v3 7.8
EPSS 0.0060
EPSS Percentile 44.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Published Apr 29, 2024
Tracked Since Feb 18, 2026