CVE-2017-16549: High severity k7 computing antivirus vulnerability
Published Jan 16, 2018
·Updated
K7 Antivirus Premium before 15.1.0.53 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a specific set of IOCTL calls.
Affected Software
7 affected components
K7Computing Antivirus<15.1.0.53
K7Computing Antivirus<15.1.0308
K7Computing Endpoint<14.2.0137
K7Computing Internet Security<15.1.0297
K7Computing Total Security<15.1.0324
K7Computing Total Security<16.0.0131
K7Computing Ultimate Security<15.1.0324
Event History
Jan 16, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-16549?
CVE-2017-16549 is considered a high-severity vulnerability due to potential privilege escalation.
2
How do I fix CVE-2017-16549?
To resolve CVE-2017-16549, update K7 Antivirus Premium to version 15.1.0.53 or later.
3
What impact does CVE-2017-16549 have on affected systems?
CVE-2017-16549 allows local users to write to arbitrary memory locations, leading to potential privilege escalation.
4
Which versions of K7 Antivirus are affected by CVE-2017-16549?
K7 Antivirus Premium versions before 15.1.0.53, as well as specific versions of K7's other products, are affected by CVE-2017-16549.
5
Can CVE-2017-16549 be exploited remotely?
CVE-2017-16549 cannot be exploited remotely as it requires local access to the system.