K7Sentry.sys in K7 Computing Ultimate Security, Anti-Virus Plus, and Total Security before 14.2.0.253 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted 0x95002570, 0x95002574, 0x95002580, 0x950025a8, 0x950025ac, or 0x950025c8 IOCTL call.
2015-02-06T15:59:11.477
2025-04-12T10:46:40.837
Deferred
CVSSv2: 7.2 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | k7computing | k7sentry.sys | ≤ 12.8.0.117 | Yes |
Application | k7computing | anti-virus_plus | ≤ 14.2.0.252 | Yes |
Application | k7computing | total_security | ≤ 14.2.0.252 | Yes |
Application | k7computing | ultimate_security | ≤ 14.2.0.252 | Yes |