First published: Fri Dec 12 2014(Updated: )
The K7Sentry.sys kernel mode driver (aka K7AV Sentry Device Driver) before 12.8.0.119, as used in multiple K7 Computing products, allows local users to cause a denial of service (NULL pointer dereference) as demonstrated by a filename containing "crashme$$".
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
K7 Computing Anti-Virus | <=12.8.0.118 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8608 has been classified as a medium severity vulnerability due to its potential for denial of service.
To fix CVE-2014-8608, upgrade the K7AV Sentry Device Driver to version 12.8.0.119 or later.
CVE-2014-8608 is a NULL pointer dereference vulnerability affecting the K7Sentry.sys kernel mode driver.
Local users of K7 Computing products using versions of the K7AV Sentry Device Driver prior to 12.8.0.119 are affected by CVE-2014-8608.
Attackers can cause a denial of service by exploiting CVE-2014-8608 with a specially crafted filename.