CVE-2014-9643
K7Sentry.sys in K7 Computing Ultimate Security, Anti-Virus Plus, and Total Security before 14.2.0.253 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted 0x95002570, 0x95002574, 0x95002580,…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.05%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
K7Sentry.sys in K7 Computing Ultimate Security, Anti-Virus Plus, and Total Security before 14.2.0.253 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted 0x95002570, 0x95002574, 0x95002580, 0x950025a8, 0x950025ac, or 0x950025c8 IOCTL call.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 1.05% probability · 62th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- k7computing/k7sentry.sys · k7computing/anti-virus plus · k7computing/total security · k7computing/ultimate security
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/130246/K7-Computing-14.2.0.240-Privilege-Escalation.htmlExploit
- http://www.exploit-db.com/exploits/35992Exploit
- http://www.greyhathacker.net/?p=818Exploit
- http://www.osvdb.org/113007
- http://packetstormsecurity.com/files/130246/K7-Computing-14.2.0.240-Privilege-Escalation.htmlExploit
- http://www.exploit-db.com/exploits/35992Exploit
- http://www.greyhathacker.net/?p=818Exploit
- http://www.osvdb.org/113007
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.