CVE-2017-16550: High severity k7 computing antivirus vulnerability
Published Jan 16, 2018
·Updated
K7 Antivirus Premium before 15.1.0.53 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a specific set of IOCTL calls.
Affected Software
7 affected components
K7Computing Antivirus<15.1.0.53
K7Computing Antivirus<15.1.0308
K7Computing Endpoint<14.2.0137
K7Computing Internet Security<15.1.0297
K7Computing Total Security<15.1.0324
K7Computing Total Security<16.0.0131
K7Computing Ultimate Security<15.1.0324
Event History
Jan 16, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-16550?
CVE-2017-16550 has a medium severity rating due to its potential to allow local users to gain elevated privileges.
2
How do I fix CVE-2017-16550?
To fix CVE-2017-16550, update K7 Antivirus Premium to version 15.1.0.53 or later.
3
What software is affected by CVE-2017-16550?
K7 Antivirus Premium, K7 Total Security, K7 Internet Security, K7 Endpoint Security, and K7 Ultimate Security versions prior to specified updates are affected by CVE-2017-16550.
4
What type of attack does CVE-2017-16550 facilitate?
CVE-2017-16550 facilitates a local privilege escalation attack through specific IOCTL calls.
5
Can CVE-2017-16550 be exploited remotely?
CVE-2017-16550 is not exploitable remotely as it requires local access to the affected system.