CVE-2014-9643: High severity K7Computing K7sentry.sys vulnerability
K7Sentry.sys in K7 Computing Ultimate Security, Anti-Virus Plus, and Total Security before 14.2.0.253 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted 0x95002570, 0x95002574, 0x95002580, 0x950025a8, 0x950025ac, or 0x950025c8 IOCTL call.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9643?
CVE-2014-9643 is rated as a high-severity vulnerability due to the potential for privilege escalation.
How do I fix CVE-2014-9643?
To mitigate CVE-2014-9643, update K7 Computing software to versions 14.2.0.253 or later.
Who is affected by CVE-2014-9643?
CVE-2014-9643 affects users of K7 Computing Ultimate Security, Anti-Virus Plus, and Total Security software below version 14.2.0.253.
What types of attacks can exploit CVE-2014-9643?
CVE-2014-9643 can be exploited by local users through crafted IOCTL calls to write to arbitrary memory locations.
What systems are vulnerable to CVE-2014-9643?
Systems running vulnerable versions of K7 Computing security products prior to 14.2.0.253 are at risk from CVE-2014-9643.