K7Computing Total Security vulnerabilities
25 known vulnerabilities affecting k7computing/total_security.
Total CVEs
25
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
HIGH19MEDIUM6
Vulnerabilities
Page 2 of 2
CVE-2017-16555HIGHCVSS 7.0fixed in 15.1.0324fixed in 16.0.01312018-01-16
CVE-2017-16555 [HIGH] CWE-787 CVE-2017-16555: K7 Antivirus Premium before 15.1.0.53 allows local users to gain privileges by sending a specific IO
K7 Antivirus Premium before 15.1.0.53 allows local users to gain privileges by sending a specific IOCTL after setting the memory in a particular way.
nvd
CVE-2017-17429MEDIUMCVSS 5.5fixed in 15.1.0324fixed in 16.0.01312018-01-16
CVE-2017-17429 [MEDIUM] CWE-20 CVE-2017-17429: In K7 Antivirus Premium before 15.1.0.53, user-controlled input to the K7Sentry device is not suffic
In K7 Antivirus Premium before 15.1.0.53, user-controlled input to the K7Sentry device is not sufficiently authenticated: a local user with a LOW integrity process can access a raw hard disk by sending a specific IOCTL.
nvd
CVE-2017-16556MEDIUMCVSS 5.5fixed in 15.1.0324fixed in 16.0.01312018-01-16
CVE-2017-16556 [MEDIUM] CWE-20 CVE-2017-16556: In K7 Antivirus Premium before 15.1.0.53, user-controlled input can be used to allow local users to
In K7 Antivirus Premium before 15.1.0.53, user-controlled input can be used to allow local users to write to arbitrary memory locations.
nvd
CVE-2017-18019HIGHCVSS 7.1PoCfixed in 15.1.0.3052018-01-04
CVE-2017-18019 [HIGH] CWE-20 CVE-2017-18019: In K7 Total Security before 15.1.0.305, user-controlled input to the K7Sentry device is not sufficie
In K7 Total Security before 15.1.0.305, user-controlled input to the K7Sentry device is not sufficiently sanitized: the user-controlled input can be used to compare an arbitrary memory address with a fixed value, which in turn can be used to read the contents of arbitrary memory. Similarly, the product crashes upon a \\.\K7Sentry DeviceIoControl call w
nvd
CVE-2014-9643HIGHCVSS 7.2PoC≤ 14.2.0.2522015-02-06
CVE-2014-9643 [HIGH] CWE-264 CVE-2014-9643: K7Sentry.sys in K7 Computing Ultimate Security, Anti-Virus Plus, and Total Security before 14.2.0.25
K7Sentry.sys in K7 Computing Ultimate Security, Anti-Virus Plus, and Total Security before 14.2.0.253 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted 0x95002570, 0x95002574, 0x95002580, 0x950025a8, 0x950025ac, or 0x950025c8 IOCTL call.
nvd
← Previous2 / 2