CVE-2017-17429
In K7 Antivirus Premium before 15.1.0.53, user-controlled input to the K7Sentry device is not sufficiently authenticated: a local user with a LOW integrity process can access a raw hard disk by sending a specific IOCTL.
Published:Jan 16, 2018
Last Modified:Nov 21, 2024
EPS:Jan 16, 2018
EPSS Score:0.00053
CVSS Score:5.5
Affected Products
Vendor
Product
Action
Vendor
K7computing
Product
Antivirus
K7computing
Antivirus
Vendor
K7computing
Product
Endpoint
K7computing
Endpoint
Vendor
K7computing
Product
Internet Security
K7computing
Internet Security
Vendor
K7computing
Product
Total Security
K7computing
Total Security
Vendor
K7computing
Product
Ultimate Security
K7computing
Ultimate Security
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
