Summary "Sygate Enterprise Protection (SEP) is the only solution that provides seamlessly integrated Host Intrusion Prevention (HIPS) and Network Access Control (NAC) Systems on a single agent, to protect managed computers, networks, and data from compromise, downtime, and theft." Improper error handling of Sygate Protection Agent allows attackers to disable and change settings of Sygate Protection Agent. Details Vulnerable Systems: * Sygate Protection Agent version 5.0 (build 6144) There are two executable files in the installation path of the agent, Smc.exe and SmcGui.exe - there are no shortcuts directly created for the user. if a standard user double clicks on the smcgui.exe, which is the management interface (supposedly not accessible to standard users), the following error is displayed: "Serious problem reading transaction from pipe - probable loss of syncronisation a 6" and the GUI does not execute. However upon killing the process in Task Manager the Management GUI appears, the user has full access to the management interface and can therefore disable the security agent.